Hill Country Memorial Hospital
ent_f4bb7fd8affee487c7323a3f
Disclosures
5
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
8,449
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hill Country Memorial Hospital
- Normalized
- hill country memorial hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- South Carolina State AGas victim2017-05-22
Hill Country Memorial Hospital notified patients that an employee's email account was accessed by an unauthorized individual on Feb 21, 2017. The actor used the account to submit fraudulent invoices. The breach may have exposed patient names, prescription/ treatment info, diagnosis, procedures, and financial account numbers. The hospital secured the account, reset passwords, reported to law enforcement, and offered one year of Equifax credit monitoring.
- Massachusetts State AGas victim2017-05-02
Hill Country Memorial Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-05-02. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-04-25
Hill Country Memorial Hospital reported that an unauthorized individual accessed an employee's email account on February 21, 2017. The actor used the access to submit fraudulent invoices. Potentially affected data includes names, addresses, SSNs, and PHI. 8,449 individuals total were affected, including 2 New Hampshire residents. Notices were mailed on April 21, 2017.
- Montana State AGas victim2017-04-25
Hill Country Memorial Hospital notified patients that an employee's email account was compromised on Feb 21, 2017, likely via phishing, leading to fraudulent invoices. The attacker may have accessed patient PII including names, prescriptions, and financial info. The hospital secured the account, changed passwords, reported to law enforcement, and offered 1 year of Equifax credit monitoring.
- TEXASHHS OCRas victim2017-04-21
Hill Country Memorial Hospital (TX) reported to HHS on 2017-04-21 a Hacking/IT Incident affecting 8,449 individuals. On February 21, 2017, a workforce member responded to a phishing email and provided credentials, enabling an unknown external actor to access her email account and send fraudulent invoices. Breached PHI on Email servers may have included names, addresses, dates of birth, Social Security numbers, and medical information. The CE notified HHS, affected individuals, and media, and implemented security awareness training and email controls. OCR obtained assurances of corrective action.