Roper St. Francis Healthcare
ent_db29ad3f4af1849b469e7ad4
Disclosures
16
HHS OCR · State AG · 5 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
189,761
nationwide · HHS OCR SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Roper St. Francis Healthcare
- Normalized
- roper st francis healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rsfh.com
Disclosure history (16)newest first
- SOUTH CAROLINAHHS OCRas victim2024-08-26
Roper St. Francis Healthcare (SC, Healthcare Provider) reported to HHS on 2024-08-26 an Unauthorized Access/Disclosure affecting 4,125 individuals. An employee inadvertently sent PHI — names only — to wrong recipients via paper/films media. The covered entity notified HHS, affected individuals, and the media, and sanctioned the responsible employee. OCR provided technical assistance regarding the HIPAA Rules. No business associate was involved.
- South Carolina State AGas victim2021-01-11
Roper St. Francis Healthcare notified individuals that unauthorized access to three employee email accounts occurred between Oct 14-29, 2020. Discovered Nov 11, 2020. Patient PII, PHI, SSNs, and DOBs were potentially accessed. Forensic investigation engaged. Credit monitoring offered.
- New Hampshire State AGas victim2021-01-11
Roper St. Francis Healthcare notified the NH Attorney General of a security incident where an unauthorized individual accessed three employees' email accounts between Oct 14-29, 2020. The breach potentially exposed names, SSNs, DOB, and medical info of 2 NH residents. RSFH engaged forensic investigators, reviewed emails, and began mailing notifications on Jan 8, 2021, offering one year of credit monitoring.
- Montana State AGas victim2021-01-08
Roper St. Francis Healthcare notified Montana residents that unauthorized access to three employee email accounts occurred between Oct 14-29, 2020. Discovered Nov 11, 2020, the incident may have exposed patient names, DOBs, medical record numbers, and PHI. Forensic investigators were engaged; email security and staff training are being enhanced.
- Massachusetts State AGas victim2021-01-08
Roper St. Francis Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-08. 13 Massachusetts residents were affected. The report records the breach type as electronic.
- SOUTH CAROLINAHHS OCRas victim2021-01-08
Roper St. Francis Healthcare reported to HHS on 2021-01-08 a Hacking/IT Incident affecting 189,761 individuals. Breached information located on Email. Multiple employees were victims of an email phishing scheme compromising PHI including names, DOB, addresses, SSNs, and medical records.
- Illinois State AGas victim2021-01-01
ROPER ST. FRANCIS HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-010). The register records the breach as discovered on November 11, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- SOUTH CAROLINAHHS OCRas victim2020-09-08
Roper St. Francis Healthcare (SC) reported a business associate ransomware attack affecting ~92,963 individuals. ePHI (names, addresses, DOB, treatment info) was compromised. CE notified HHS, individuals, and media.
- Montana State AGas victim2020-09-04
Roper St. Francis Healthcare notified Montana residents that an unauthorized individual accessed an employee's email account between June 13-17, 2020. The incident exposed names, DOBs, medical record numbers, and limited clinical info. The company engaged forensic investigators and enhanced email security.
- SOUTH CAROLINAHHS OCRas victim2020-09-03
Roper St. Francis Healthcare reported to HHS on 2020-09-03 a Hacking/IT Incident affecting 6000 individuals. Breached information located on Email. An employee was victim of an email phishing scheme compromising PHI including names, addresses, phone numbers, dates of birth, diagnoses, and treatment information. The entity provided credit monitoring and implemented technical safeguards.
- SOUTH CAROLINAHHS OCRas victim2020-01-17
Roper St. Francis Healthcare reported to HHS on 2020-01-17 an Improper Disposal affecting 1,634 individuals. Breached information located on Paper/Films. Documents containing PHI (names, diagnoses, lab results, medications) were disposed of in regular trash. The responsible employee was sanctioned and staff retrained.
- Illinois State AGas victim2020-01-01
ROPER ST FRANCIS HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-338). The register records the breach as discovered on July 8, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
ROPER ST FRANCIS HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-343). The register records the breach as discovered on July 31, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- SOUTH CAROLINAHHS OCRas victim2019-01-29
Roper St. Francis Healthcare reported to HHS on 2019-01-29 a Hacking/IT Incident affecting 35253 individuals. Breached information located on Email. Employees followed phishing links and provided credentials, allowing unauthorized access to PHI.
- Illinois State AGas victim2019-01-01
ROPER ST. FRANCIS HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-016). The register records the breach as discovered on November 15, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- SOUTH CAROLINAHHS OCRas victim2017-01-24
Roper St. Francis Healthcare (Mount Pleasant Hospital, SC) reported to HHS on 2017-01-24 a Loss affecting 576 individuals. A portable camera containing infant security photos (PHI: patient photographs, last names, dates of birth, providers' names) went missing after a nurse failed to store it in its normal secure location. The breach affected 508 newborn patients. Breached information located on Other Portable Electronic Device. The CE discontinued the photo procedure, implemented an incident response procedure, trained staff, and offered credit monitoring to affected individuals.