Columbia University Irving Medical Center
ent_ea1f10255fb0f9b52639b76f
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
29,629
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Columbia University Irving Medical Center
- Normalized
- columbia university irving medical center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Montana State AGas victim2024-05-07
Columbia University Irving Medical Center notified Montana residents that a workforce member inadvertently made a file containing patient lab data available on a third-party internet platform in August 2023. Evidence of potential access by unknown third parties was identified on March 8, 2024. Data included names, DOB, medical record numbers, and single lab results. No SSNs or financial data were involved.
- NEW YORKHHS OCRas victim2024-05-06
Columbia University Irving Medical Center reported to HHS on 2024-05-06 a Unauthorized Access/Disclosure affecting 29,629 individuals. Breached information located on Network Server. An employee posted PHI including names, DOBs, and lab results on the Internet.
- Illinois State AGas victim2024-05-01
COLUMBIA UNIVERSITY IRVING MEDICAL CENTER filed a data-breach notice with the Illinois Attorney General in May 2024 (case 24-05-016). The register records the breach as discovered on September 11, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2013-05-06
Columbia University Medical Center inadvertently emailed an Excel file containing residency match lists and hidden Social Security Numbers to students, faculty, and staff on March 15, 2013. 407 medical students were affected. The incident was detected immediately, emails were deleted, and 12 months of credit monitoring was offered. One New Hampshire resident was notified on April 19, 2013.