Northern Light Health
ent_8f39ce7d0fc0f73ea8d14991
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
304,399
nationwide · HHS OCR ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Northern Light Health
- Normalized
- northern light health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- northernlighthealth.org
Disclosure history (5)newest first
- California State AGas victim2020-09-14
Northern Light Health notified individuals of a ransomware attack on its third-party vendor, Blackbaud, Inc., in May 2020. The attack resulted in the exfiltration of limited protected health information, including names, addresses, dates of birth, and medical service details. Blackbaud paid the ransom. Northern Light Health notified HHS and established a call center for affected individuals.
- Montana State AGas victim2020-09-14
Northern Light Health notified Montana and other residents of a third-party vendor (Blackbaud) ransomware incident. The attack occurred in May 2020; Northern Light Health was notified on July 16, 2020. Data involved included names, addresses, DOB, gender, and limited PHI. Ransom was paid by Blackbaud. No credit card data was accessed. Total affected count not explicitly stated for Montana; 487 Rhode Island residents identified.
- MAINEHHS OCRas victim2020-08-03
Northern Light Health reported to HHS on 2020-08-03 a Hacking/IT Incident affecting 304,399 individuals. Breached information located on Network Server, Other. The covered entity's business associate experienced a ransomware attack affecting ePHI including names, addresses, and dates of birth. The CE notified HHS, affected individuals, the media, and provided substitute notice.
- Illinois State AGas victim2020-01-01
NORTHERN LIGHT HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-388). The register records the breach as discovered on September 14, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
NORTHERN LIGHT HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-358). The register records the breach as discovered on May 14, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- Northern Light Health’s filing is one of at least 175 in the BLACKBAUD, INC. supply-chain incident (2020).