St. Mary's Health
ent_f4b523b59fc218ee32ceec52
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,952
nationwide · HHS OCR IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- St. Mary's Health
- Normalized
- st mary s health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Illinois State AGas victim2022-01-01
ST. MARY'S HEALTH D/B/A ST VINCENT EVANSVILLE filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-063). The register records the breach as discovered on March 22, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2018-05-31
St. Mary's Health, Inc. d/b/a St. Vincent Evansville disclosed a cybersecurity incident discovered on Feb 12, 2018. A configuration error on a credentialing software server exposed patient/staff PII (names, DOB, SSN, DLs) to the internet. Unauthorized external actors attempted to download data. The server was taken offline and reconfigured. No evidence of data misuse or dark web posting was found. Affected individuals were offered 1 year of Experian IdentityWorks.
- New Hampshire State AGas victim2018-05-31
St. Mary's Health, Inc. d/b/a St. Vincent Evansville notified the NH Attorney General of a data incident affecting 4 New Hampshire residents. On February 12, 2018, the hospital detected unusual internet traffic accessing a server hosting credentialing software. Investigation revealed a server configuration error that exposed data to the internet. The server was taken offline and reconfigured. Forensic analysis indicated unauthorized access attempts from outside the US, but no evidence of data posting to the dark web was found. Affected data included names, addresses, dates of birth, phone numbers, driver's licenses, SSNs, and National Provider Data Bank reports. The hospital offered one year of identity theft monitoring.
- INDIANAHHS OCRas victim2015-03-05
St. Mary's Health (Indiana) reported to HHS on 2015-03-05 a Hacking/IT Incident affecting 3,952 individuals. On December 3, 2014, a phishing email attack compromised several employees' usernames and passwords. Exposed PHI included patient names, addresses, dates of birth, clinical information, and in some cases, Social Security numbers. Breached information was located in Email systems. OCR obtained documented assurances of corrective action, including deployment of a phishing/malware awareness program.