Centura Health
ent_f83be9da072ac1338fb09281
Disclosures
3
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
12,286
as filed · HHS OCR CO
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Centura Health
- Normalized
- centura health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- COHHS OCRas victim2021-06-12
Centura Health (CO) reported to HHS on 2021-06-12 a Hacking/IT Incident (email phishing scheme) affecting 738 individuals. An employee was the victim of a phishing attack that exposed PHI including names, dates of birth, diagnoses, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and media, and implemented additional technical and administrative safeguards.
- COHHS OCRas victim2019-05-22
Centura Health (CO) reported to HHS on 2019-05-22 a Hacking/IT Incident (email phishing) affecting 7,515 individuals. Several employees were victims of an email phishing scheme exposing ePHI including names, dates of birth, diagnoses, and other treatment information. Breached information was located in Email. The CE notified HHS, affected individuals, and the media, implemented additional administrative and technical safeguards, retrained staff, and received HIPAA Security Rule technical assistance from OCR.
- COHHS OCRas victim2014-04-22
Centura Health (Colorado Healthcare Provider) reported to HHS OCR on 2014-04-22 a Hacking/IT Incident affecting 12,286 individuals. Employees inadvertently responded to a phishing email by clicking a fraudulent link and surrendering their usernames and passwords, enabling attacker access to those email accounts. Breached ePHI included demographic (names, addresses, DOB, phone numbers, SSNs), clinical (diagnoses, lab results, medications), and financial (claims) information. The CE notified HHS, affected individuals, media, and the FBI, and offered free credit monitoring. Corrective actions included updated risk management, employee retraining, and enhanced phishing-awareness education. OCR confirmed corrective action implementation.