Upstate HomeCare
ent_ce2962923330e02113b8ae7e
Disclosures
6
State AG · HHS OCR · Leak Site · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
5,114
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Upstate HomeCare
- Normalized
- upstate homecare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Massachusetts State AGas victim2021-11-24
Upstate HomeCare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-11-24. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2021-11-24
Upstate HomeCare, a healthcare entity based in New York, reported an external system breach (hacking) discovered on November 4, 2021. The incident affected a total of 5,114 individuals, including 1 Maine resident. Notification letters were sent on November 24, 2021, offering 12 months of identity monitoring services through Kroll, including credit monitoring and fraud consultation.
- NEW YORKHHS OCRas victim2021-11-24
Upstate HomeCare reported to HHS on 2021-11-24 a Hacking/IT Incident affecting 5,114 individuals. Breached information located on Network Server. The attack exposed PHI including names, SSNs, addresses, driver's license numbers, DOB, financial/claims info, diagnoses, and medications. Response included credit monitoring, security safeguards, and workforce retraining.
- GLOBALLeak Siteas victim2021-09-09
- GLOBALLeak Siteas victim2021-09-09
- Illinois State AGas victim2021-01-01
UPSTATE HOME CARE filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-477). The register records the breach as discovered on November 4, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.