Virginia Department of Behavioral Health and Developmental Services
ent_a63207e5232e6c8872d120c4
Disclosures
4
HHS OCR · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
4,037
nationwide · HHS OCR VA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Virginia Department of Behavioral Health and Developmental Services
- Normalized
- virginia department of behavioral health and developmental— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- VIRGINIAHHS OCRas victim2026-04-07
Virginia Department of Behavioral Health and Developmental Services reported to HHS OCR on 2026-04-07 an Unauthorized Access/Disclosure breach affecting 724 individuals. Breached information was located on Email. No business associate was involved. No further detail is available in the web description.
- VIRGINIAHHS OCRas victim2021-12-03
Virginia Department of Behavioral Health and Developmental Services reported to HHS on 2021-12-03 a Unauthorized Access/Disclosure affecting 4037 individuals. Breached information located on Network Server. PHI, including names, addresses, SSNs, and DOBs, was made public on a funding portal. The portal was removed from service and credit monitoring was offered.
- VIRGINIAHHS OCRas victim2020-03-20
Virginia Department of Behavioral Health and Developmental Services reported to HHS on 2020-03-20 a Unauthorized Access/Disclosure affecting 657 individuals. Breached information located on Email. An employee inadvertently emailed ePHI (names, member IDs, clinical info) to the wrong recipient. The CE notified HHS, affected individuals, and the media, and revised policies and procedures.
- VIRGINIAHHS OCRas victim2019-10-25
Virginia Department of Behavioral Health & Developmental Services reported to HHS on 2019-10-25 a Unauthorized Access/Disclosure affecting 1442 individuals. Breached information located on Network Server. Note: OCR investigation determined the entity is not a covered entity.