Northwood, Inc.
ent_b5abc1fed43679e9b43d8b79
Disclosures
11
HHS OCR · State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
86,050
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Northwood, Inc.
- Normalized
- northwood— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- northwoodinc.com
Disclosure history (11)newest first
- MICHIGANHHS OCRas victim2019-07-16
Northwood, Inc. (Business Associate, MI) reported to HHS OCR on 2019-07-16 an Unauthorized Access/Disclosure breach affecting 3,881 individuals. Breached information was located in Email. HHS noted this review has been consolidated with another review of the same entity involving the same facts.
- MICHIGANHHS OCRas victim2019-07-16
Northwood, Inc., a Business Associate (BA) of Blue Care Network and Blue Cross Blue Shield of Michigan (MI), reported to HHS on 2019-07-16 an Unauthorized Access/Disclosure affecting 583 individuals (approximately 18,684 per the description). An employee was the victim of an email phishing scheme exposing PHI including names, addresses, dates of birth, health insurance information, and treatment information. Breached information located on Email. Northwood notified HHS, affected individuals, the media, and the FBI, and implemented additional administrative, technical, and security safeguards. OCR obtained assurances of corrective action.
- Massachusetts State AGas victim2019-07-15
Northwood, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-07-15. 1,518 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-07-15
Northwood, Inc. notified Montana residents of a phishing incident where an employee's email credentials were compromised. Unauthorized access occurred May 3-6, 2019. The account contained PHI regarding healthcare provider exclusion status with CMS. Northwood contained the account, reset passwords, implemented MFA, and provided 2 years of identity monitoring.
- Oregon State AGas victim2019-07-15
Northwood, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-07-15. The breach occurred during 5/3/2019 - 5/6/2019. The breach was discovered on 5/6/20196/19/2019. 86,050 individuals were affected. Notice was sent on 7/12/20197/15/2019.
- California State AGas victim2019-07-15
Northwood, Inc., a durable medical equipment supplier, experienced a data breach after an employee fell victim to a phishing email that captured login credentials. An unauthorized individual accessed the employee's email account between May 3 and May 6, 2019. The account contained protected health information (PHI) regarding healthcare providers' exclusion status with CMS. Northwood contained the incident by taking the account offline, resetting passwords, and implementing MFA. Affected individuals were offered two years of identity monitoring.
- MICHIGANHHS OCRas victim2019-07-15
Northwood, Inc reported to HHS on 2019-07-15 a Unauthorized Access/Disclosure affecting 5563 individuals. Breached information located on Email. An employee was victim of an email phishing scheme affecting PHI including names, addresses, DOB, and health insurance info. Northwood notified HHS, individuals, media, and FBI, and implemented additional safeguards.
- Washington State AGas victim2019-07-15
Northwood, Inc. reported a phishing incident in Washington affecting 1,185 residents. Unauthorized access to an employee email account occurred May 3-6, 2019, via stolen credentials. PII exposed included names and SSNs. Northwood secured the account, reset passwords, implemented MFA, and offered 2 years of credit monitoring.
- New Hampshire State AGas victim2019-07-15
Northwood, Inc. notified the NH AG of a phishing incident affecting 386 NH residents. An employee email account was compromised between May 3-6, 2019, exposing names and SSNs of healthcare providers. Northwood engaged forensic experts, secured the account, and offered 2 years of credit monitoring.
- MICHIGANHHS OCRas victim2019-07-12
Northwood, Inc. reported to HHS on 2019-07-12 a Unauthorized Access/Disclosure affecting 18,684 individuals. Breached information located on Email. An employee was victim of an email phishing scheme affecting PHI including names, addresses, DOB, and treatment info. Northwood notified HHS, individuals, media, and FBI, and implemented additional safeguards.
- Illinois State AGas victim2019-01-01
NORTHWOOD, INC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-258). The register records the breach as discovered on May 3, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.