UPMC Susquehanna
ent_f1bd670956750904b957acd5
Disclosures
2
HHS OCR · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,208
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UPMC Susquehanna
- Normalized
- upmc susquehanna— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- FEDERALHHS OCRas victim2017-11-15
UPMC Susquehanna reported to HHS on 2017-11-15 a Hacking/IT Incident affecting 1208 individuals. An unauthorized individual gained access to 11 staff email accounts via a phishing email, exposing protected health information including names, dates of birth, social security numbers, addresses, and clinical information. The breach location was Email. In response, the entity implemented stricter password policies and two-factor authentication.
- PAHHS OCRas victim2014-03-27
Susquehanna Health reported to HHS on 2014-03-27 a Unauthorized Access/Disclosure affecting 657 individuals. Breached information located on Email. An employee impermissibly disclosed PHI to an insurer during a routine claims request, including names, SSNs, DOBs, and diagnosis codes. The entity notified HHS and individuals, offered credit monitoring, and ensured data deletion/shredding.