Sunrise Community Health
ent_d84dc21731cea937f4c770d6
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
18,404
nationwide · HHS OCR CO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sunrise Community Health
- Normalized
- sunrise community health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2020-05-15
Sunrise Community Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-05-15. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- COLORADOHHS OCRas victim2019-12-05
Sunrise Community Health (a Colorado healthcare provider) reported to HHS OCR on 2019-12-05 that several employees fell victim to an email phishing scheme, compromising ePHI of 18,404 individuals. Affected data included names, dates of birth, diagnoses, medications prescribed, and other treatment information. The entity notified HHS, affected individuals, the media, and provided substitute notice. Remediation included additional administrative, technical, and security safeguards plus workforce retraining on email security. OCR provided technical assistance on HIPAA Security Rule obligations.
- Montana State AGas victim2019-12-05
Sunrise Community Health reported a data breach to the Montana Attorney General. The breach was reported on 2019-12-05. The breach occurred from 9/11/2019 to 11/22/2019. 1 Montana residents were affected.
- Illinois State AGas victim2019-01-01
SUNRISE COMMUNITY HEALTH filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-480). The register records the breach as discovered on October 1, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.