Northwood
ent_d1dad46cfbdd1d6b9cffe3bf
Disclosures
7
HHS OCR · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
86,050
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Northwood
- Normalized
- northwood— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500C040DCDFCB1347
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- northwoodmfg.com
Disclosure history (7)newest first
- MIHHS OCRas victim2019-07-16
Northwood, Inc. (Business Associate, MI) reported to HHS OCR on 2019-07-16 an Unauthorized Access/Disclosure breach affecting 3,881 individuals. Breached information was located in Email. HHS noted this review has been consolidated with another review of the same entity involving the same facts.
- MIHHS OCRas victim2019-07-16
Northwood, Inc., a Business Associate (BA) of Blue Care Network and Blue Cross Blue Shield of Michigan (MI), reported to HHS on 2019-07-16 an Unauthorized Access/Disclosure affecting 583 individuals (approximately 18,684 per the description). An employee was the victim of an email phishing scheme exposing PHI including names, addresses, dates of birth, health insurance information, and treatment information. Breached information located on Email. Northwood notified HHS, affected individuals, the media, and the FBI, and implemented additional administrative, technical, and security safeguards. OCR obtained assurances of corrective action.
- 🦬Montana State AGas victim2019-07-15
Northwood reported a data breach to the Montana Attorney General. The breach was reported on 2019-07-15. The breach occurred from 5/3/2019 to 5/6/2019. 180 Montana residents were affected.
- 🦫Oregon State AGas victim2019-07-15
Northwood, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-07-15. The breach occurred during 5/3/2019 - 5/6/2019. The breach was discovered on 5/6/20196/19/2019. 86,050 individuals were affected. Notice was sent on 7/12/20197/15/2019.
- 🐻California State AGas victim2019-07-15
Northwood, Inc., a durable medical equipment supplier, notified California residents of a data breach occurring between May 3 and May 6, 2019. An employee's email credentials were compromised via a phishing email, allowing unauthorized access to the account. The account contained healthcare provider exclusion status information (PHI). Northwood contained the breach, reset credentials, implemented MFA, and offered 2 years of credit monitoring via Kroll.
- MIHHS OCRas victim2019-07-15
Northwood, Inc reported to HHS on 2019-07-15 a Unauthorized Access/Disclosure affecting 5563 individuals. Breached information located on Email. An employee was victim of an email phishing scheme affecting PHI including names, addresses, DOB, and health insurance info. Northwood notified HHS, individuals, media, and FBI, and implemented additional safeguards.
- MIHHS OCRas victim2019-07-12
Northwood, Inc. reported to HHS on 2019-07-12 a Unauthorized Access/Disclosure affecting 18,684 individuals. Breached information located on Email. An employee was victim of an email phishing scheme affecting PHI including names, addresses, DOB, and treatment info. Northwood notified HHS, individuals, media, and FBI, and implemented additional safeguards.