Veterans Health Administration
ent_eacecba99ceb829ee424f8f8
Disclosures
6
HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
46,677
as filed · HHS OCR DC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Veterans Health Administration
- Normalized
- veterans health administration— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- va.gov
Disclosure history (6)newest first
- DCHHS OCRas victim2025-01-13
Veterans Health Administration (DC) reported to HHS on 2025-01-13 an Unauthorized Access/Disclosure affecting 1,847 individuals. An employee of its business associate mailed PHI — including names, addresses, and treatment information — to wrong recipients. PHI was located on Paper/Films. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. The BA implemented additional administrative safeguards as mitigation.
- FEDERALHHS OCRas victim2024-12-03
Veterans Health Administration reported to HHS on 2024-12-03 a Hacking/IT Incident affecting 2302 individuals, which was the result of a ransomware attack on a business associate. The breach compromised names, Social Security numbers, and medical information located on a network server.
- DCHHS OCRas victim2024-01-30
Veterans Health Administration (VHA) reported to HHS on 2024-01-30 an Unauthorized Access/Disclosure affecting 46,677 individuals. A vendor employee mailed PHI — including names and treatment information — to incorrect recipients. Breached information was located on Paper/Films. VHA notified HHS, affected individuals, and the media. In response, additional administrative, technical, and security safeguards were implemented, and staff were retrained on sensitive data protection requirements.
- DCHHS OCRas victim2024-01-05
Veterans Health Administration (VHA) reported to HHS on 2024-01-05 an Unauthorized Access/Disclosure affecting 2,380 individuals. A business associate mailed appointment reminder letters containing PHI (names, addresses, and appointment information) to wrong recipients. Breached information located on Paper/Films. VHA notified HHS, affected individuals, and the media. CE and BA implemented additional administrative safeguards in response.
- DCHHS OCRas victim2020-09-14
Veterans Health Administration reported to HHS on 2020-09-14 a Hacking/IT Incident affecting 44308 individuals. Breached information located on Network Server. The cyber-attack affected electronic protected health information (ePHI) including names, Social Security numbers, and clinical information. The entity notified HHS, affected individuals, and the media, provided complimentary credit monitoring, and implemented additional technical safeguards.
- DCHHS OCRas victim2018-11-06
Veterans Health Administration (VHA) reported to HHS on 2018-11-06 an Unauthorized Access/Disclosure affecting 19,254 individuals. On August 8 and September 4, 2018, business associate Xerox Corporation erroneously printed appointment reminder cards for patients that were mailed to another patient, exposing demographic and clinical information. The BA implemented additional controls including joint CE/BA template review and a match alert notification. OCR reviewed the BA agreement, notification letters, and security measures, and obtained assurances of corrective action.