Harrisburg Medical Center
ent_a75c0773a062a7b86755d42d
Disclosures
10
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
147,826
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Harrisburg Medical Center
- Normalized
- harrisburg medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Vermont State AGas victim2023-12-12
Harrisburg Medical Center notified consumers of a data breach where an unknown third party accessed systems from Dec 19-23, 2022. Affected data included names, SSNs, DOBs, clinical info, and for some, driver's license and financial account numbers. HMC engaged forensic investigators and law enforcement, enhanced security measures, and offered one year of Equifax credit monitoring.
- Massachusetts State AGas victim2023-12-12
Harrisburg Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-12. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-12-12
Harrisburg Medical Center notified the New Hampshire Attorney General of a cybersecurity incident affecting 3 NH residents. Unauthorized access occurred between Dec 19-23, 2022. Personal information was accessed. No evidence of harm or misuse was found. Affected individuals received notification letters and complimentary credit monitoring.
- Montana State AGas victim2023-12-12
Harrisburg Medical Center notified individuals of unauthorized access to its computer network between Dec 19-23, 2022. The incident exposed names, SSNs, DOBs, clinical data, and in some cases financial and ID numbers. The company engaged forensic investigators and law enforcement, enhanced security measures, and offered one year of Equifax credit monitoring.
- Maine State AGas victim2023-12-12
Harrisburg Medical Center (HMC) reported an external system breach occurring between December 19 and 23, 2022, discovered on August 24, 2023. The incident affected 147,826 individuals, including one Maine resident. The breach involved the acquisition of names and Social Security Numbers. HMC provided written notification and 12 months of Equifax Complete Premier identity theft protection services.
- ILLINOISHHS OCRas victim2023-02-21
Harrisburg Medical Center reported to HHS on 2023-02-21 a Hacking/IT Incident affecting 147,826 individuals. Breached information located on Network Server. The incident compromised PHI including names, addresses, DOB, SSN, driver's license, financial info, diagnoses, and lab results. The CE implemented additional technical and security safeguards.
- Illinois State AGas victim2023-01-01
HARRISBURG MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-084). The register records the breach as discovered on December 23, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
HARRISBURG MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-460). The register records the breach as discovered on July 8, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGas victim2020-06-02
Harrisburg Medical Center, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-02-19 and was reported on 2020-06-02. 18 Indiana residents were affected. 1,944 individuals affected in total.
- Illinois State AGas victim2020-01-01
HARRISBURG MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-221). The register records the breach as discovered on March 20, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.