Rutland Regional Medical Center
ent_e19cec5b4d361032d750b397
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
665
nationwide · HHS OCR VT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Rutland Regional Medical Center
- Normalized
- rutland regional medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- New Hampshire State AGas victim2019-03-19
Rutland Regional Medical Center notified NH AG of unauthorized access to 9 employee email accounts between Nov 2, 2018 and Feb 6, 2019. Incident discovered Dec 29, 2018. Affected data included names, SSNs (part of Medicare HCINs), and demographic billing info. 20 NH residents notified. Credit monitoring provided.
- Massachusetts State AGas victim2019-03-15
Rutland Regional Medical Center reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-15. 12 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-03-12
Rutland Regional Medical Center notified Montana residents of a data security incident involving unauthorized access to nine employee email accounts. The incident stemmed from a phishing email sent on Dec 21, 2018, leading to credential compromise between Nov 2, 2018, and Feb 6, 2019. Affected data included demographic information used for healthcare billing. The company engaged forensic experts and provided 24 months of identity protection services.
- VERMONTHHS OCRas victim2017-06-16
Rutland Regional Medical Center reported to HHS on 2017-06-16 a Unauthorized Access/Disclosure affecting 665 individuals. Breached information located on Email. The covered entity sent patient surveys via email with recipient addresses in the 'To' line, exposing patient names and email addresses to all other recipients. The CE provided breach notification to HHS, affected individuals, and the media, and set up an assistance help line. As a result of OCR's investigation, the CE revised its policies regarding using and disclosing protected health information and sending patient emails, and re-trained its staff on its HIPAA policies.