Community Memorial Health System
ent_ce05220d802a6fbf8309aee0
Disclosures
7
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
14,798
nationwide · HHS OCR KS
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Community Memorial Health System
- Normalized
- community memorial health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Massachusetts State AGas victim2024-02-25
Community Memorial Healthcare, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-25. 6 Massachusetts residents were affected.
- Montana State AGas victim2024-01-26
Community Memorial Healthcare, Inc (a Kansas hospital) disclosed a network security incident detected on October 18, 2023. An unauthorized third party accessed and disabled some systems, potentially exposing patient and employee data including names, addresses, SSNs, and clinical information. The company engaged forensic specialists, notified law enforcement, rebuilt systems, and offered credit monitoring.
- KANSASHHS OCRas victim2023-12-16
Community Memorial Healthcare, Inc. (KS) reported to HHS on 2023-12-16 a Hacking/IT Incident (ransomware attack) affecting 14,798 individuals. Breached PHI located on a Network Server included names, addresses, dates of birth, Social Security numbers, claims information, and diagnoses. The CE notified HHS, affected individuals, and the media, and provided complimentary credit monitoring services.
- California State AGas victim2021-07-16
Guidehouse, a professional services provider, notified the California Attorney General of a cyber attack occurring in late January 2021. The attack compromised a third-party secure file transfer service used by Guidehouse, affecting data for clients including Community Memorial Health System in Ventura, CA. Guidehouse discovered the incident in late March 2021. Affected data may include names, dates of birth, member IDs, addresses, and certain medical information. Guidehouse ceased using the compromised service, engaged cybersecurity experts, and cooperated with federal law enforcement. Affected individuals were offered two years of credit monitoring.
- California State AGas victim2020-04-27
Community Memorial Health System (CMHS) notified employees of a data breach at third-party vendor PaperlessPay Corporation. DHS alerted PaperlessPay on February 19, 2020 that an unknown individual was selling access to their client database on the dark web. The unauthorized person accessed PaperlessPay's SQL server on February 18, 2020, where CMHS employee pay stub and tax form data was stored, including names, addresses, SSNs, pay/withholdings, and in some cases bank account numbers. CMHS offered one year of free Experian IdentityWorks to affected employees.
- CALIFORNIAHHS OCRas victim2017-09-05
On June 22, 2017, Community Memorial Health System (CA) experienced a phishing incident in which several hundred staff members received phishing emails. One employee working remotely followed the link, compromising her account credentials. The breach affected 959 individuals. Breached information was located in Email systems. The CE notified HHS, affected individuals, and media, disabled remote/mobile access, required credential resets, enforced two-factor authentication, and deployed centralized server log monitoring. OCR obtained corrective action assurances.
- California State AGas victim2017-09-05
Community Memorial Health System reported that an employee's email account was compromised via a phishing email on June 22, 2017. The employee noticed anomalies on June 23, 2017, leading to a password reset and investigation. The compromised account contained patient names, medical record numbers, dates of service, and certain health information. Some records may have included Social Security Numbers. Forensic analysis indicated it is highly unlikely personal information was accessed, but notice was provided as a precaution. Credit monitoring was offered.
Supply-chain cascadesreviewed and confirmed
- Community Memorial Health System’s filing is one of at least 13 in the PaperlessPay Corporation supply-chain incident (2020).