UnityPoint Health
ent_dab4354f93cde71f8982a1c2
Disclosures
19
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,421,107
nationwide · HHS OCR IA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UnityPoint Health
- Normalized
- unitypoint health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- unitypoint.org
Disclosure history (19)newest first
- Illinois State AGas reporting2024-03-01
UNITY POINT CLINIC filed a data-breach notice with the Illinois Attorney General in March 2024 (case 24-03-049). The register records the breach as discovered on February 20, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2024-03-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General in March 2024 (case 24-03-048). The register records the breach as discovered on February 22, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2024-02-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General in February 2024 (case 24-02-039). The register records the breach as discovered on January 22, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-184). The register records the breach as discovered on December 20, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-798). The register records the breach as discovered on September 22, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-197). The register records the breach as discovered on December 22, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-180). The register records the breach as discovered on December 22, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-191). The register records the breach as discovered on December 14, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-611). The register records the breach as discovered on August 29, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
UNITY POINT HEALTH filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-632). The register records the breach as discovered on September 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2020-09-14
UnityPoint Health notified Montana residents of a third-party data breach involving Blackbaud, a fundraising software provider. Cybercriminals conducted a ransomware attack between Feb 7 and May 20, 2020, exfiltrating and encrypting data. Compromised data included names, addresses, DOBs, phone numbers, provider names, dates of service, and philanthropic history. No SSNs or financial account info were exposed. Blackbaud paid a ransom and engaged forensic experts.
- Massachusetts State AGas victim2018-07-30
UnityPoint Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-07-30. 178 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-07-30
UnityPoint Health notified Montana residents of a phishing attack that compromised employee email accounts between March 14 and April 3, 2018. Discovered May 31, 2018, the incident exposed PHI and PII (SSN, DOB, DL) via email attachments. No known misuse reported. Remediation included MFA, password resets, and employee training.
- IOWAHHS OCRas victim2018-07-30
Iowa Health System d/b/a UnityPoint Health reported to HHS on 2018-07-30 a Hacking/IT Incident affecting 1,421,107 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme compromising PHI including names, DOB, SSN, driver's license, claims, financial info, diagnoses, lab results, and medications. The CE implemented additional safeguards and retrained staff.
- New Hampshire State AGas victim2018-07-30
UnityPoint Health notified the NH Attorney General on July 30, 2018, of a phishing incident discovered May 31, 2018. Attackers gained access to employee email accounts between March 14 and April 3, 2018, potentially exposing PHI and PII (including SSNs and driver's licenses) of 52 NH residents. No misuse reported. Remediation included MFA, password resets, and employee training. Credit monitoring offered.
- Montana State AGas reporting2018-07-30
Plant Therapy notified Montana residents of a data security incident discovered on July 20, 2018, involving its e-commerce platform. The incident potentially exposed names, usernames, passwords, and payment card details. The company reset passwords, engaged forensic investigators, and reported the incident to the FBI and payment card brands. Affected individuals were offered 24 months of identity protection services.
- California State AGas victim2018-07-30
UnityPoint Health disclosed a phishing attack that compromised employee email accounts between March 14 and April 3, 2018. The incident was discovered on May 31, 2018. Attackers used fraudulent emails to trick employees into providing credentials, gaining access to protected health information and personal data including SSNs and financial account numbers. The attack was financially motivated, likely aimed at diverting funds, though patient data was exposed. UnityPoint reset passwords, implemented MFA, and offered credit monitoring.
- IOWAHHS OCRas victim2018-04-16
Iowa Health System d/b/a UnityPoint Health reported to HHS on 2018-04-16 a Hacking/IT Incident affecting 16,429 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme compromising PHI including names, DOB, SSN, driver's license, claims, financial info, diagnoses, lab results, and medications. The CE implemented additional safeguards and retrained staff.
- IOWAHHS OCRas victim2013-10-02
UnityPoint Health Affiliated reported to HHS on 2013-10-02 a Unauthorized Access/Disclosure affecting 1825 individuals. Breached information located on Electronic Medical Record. An office manager used physicians' passwords to access patient PHI including names, SSNs, and diagnoses.