UnityPoint Health
ent_dab4354f93cde71f8982a1c2
Disclosures
6
State AG · HHS OCR · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,421,107
nationwide · HHS OCR IA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UnityPoint Health
- Normalized
- unitypoint health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- unitypoint.org
Disclosure history (6)newest first
- 🦬Montana State AGas victim2020-09-14
UnityPoint Health reported a data breach to the Montana Attorney General. The breach was reported on 2020-09-14. The breach occurred from 2/7/2020 to 5/20/2020. 4 Montana residents were affected.
- IOWAHHS OCRas victim2018-07-30
Iowa Health System d/b/a UnityPoint Health reported to HHS on 2018-07-30 a Hacking/IT Incident affecting 1,421,107 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme compromising PHI including names, DOB, SSN, driver's license, claims, financial info, diagnoses, lab results, and medications. The CE implemented additional safeguards and retrained staff.
- 🦬Montana State AGas victim2018-07-30
UnityPoint reported a data breach to the Montana Attorney General. The breach was reported on 2018-07-30. The breach occurred from 3/14/2018 to 4/3/2018. 144 Montana residents were affected.
- 🐻California State AGas victim2018-07-30
California AG breach notification for UnityPoint Health regarding a phishing attack on business email systems between March 14 and April 3, 2018, discovered May 31, 2018. Attackers obtained credentials via phishing emails, accessing accounts containing patient PHI and PII (SSN, DOB, financial data). No known misuse reported. Remediation included password resets, MFA, employee training, and free credit monitoring.
- IOWAHHS OCRas victim2018-04-16
Iowa Health System d/b/a UnityPoint Health reported to HHS on 2018-04-16 a Hacking/IT Incident affecting 16,429 individuals. Breached information located on Email. Employees were subjects of an email phishing scheme compromising PHI including names, DOB, SSN, driver's license, claims, financial info, diagnoses, lab results, and medications. The CE implemented additional safeguards and retrained staff.
- IOWAHHS OCRas victim2013-10-02
UnityPoint Health Affiliated reported to HHS on 2013-10-02 a Unauthorized Access/Disclosure affecting 1825 individuals. Breached information located on Electronic Medical Record. An office manager used physicians' passwords to access patient PHI including names, SSNs, and diagnoses.