Sentara Healthcare
ent_fae290225f8cb4cda116bf57
Disclosures
6
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
72,121
as filed · HHS OCR VA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sentara Healthcare
- Normalized
- sentara healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sentara.com
Disclosure history (6)newest first
- VAHHS OCRas victim2023-02-24
Sentara Healthcare reported to HHS on 2023-02-24 a Unauthorized Access/Disclosure affecting 741 individuals. Breached information located on Network Server. A business associate employee posted a file containing PHI (names, health insurance, claims/treatment) online. CE provided credit monitoring.
- VAHHS OCRas victim2022-08-01
Sentara Williamsburg Regional Medical Center reported to HHS on 2022-08-01 a Loss affecting 591 individuals. Breached information located on Other. A manometry system containing PHI (names, DOB, diagnoses, treatment info) was missing. The CE implemented additional administrative safeguards.
- VAHHS OCRas victim2021-11-19
Sentara Healthcare (VA) reported to HHS OCR on 2021-11-19 that its business associate experienced a ransomware attack affecting the PHI of 72,121 individuals. Breached information was located on a Network Server. Exposed data included addresses, Social Security numbers, dates of birth, and other identifiers. The covered entity notified HHS, affected individuals, and the media. OCR provided technical assistance regarding the Breach Notification Rule.
- VAHHS OCRas victim2017-01-16
Sentara Healthcare reported to HHS on 2017-01-16 a Hacking/IT Incident affecting 5454 individuals. Breached information located on Network Server. The incident involved business associate Medstreaming, where a cybersecurity incident impacted vascular and thoracic patient records (2012-2015). The CE and BA hired forensic teams, rebuilt the platform, and improved technical safeguards.
- VAHHS OCRas victim2015-10-02
Sentara Healthcare (VA) reported to HHS OCR on 2015-10-02 a theft affecting 1,040 individuals. On or about August 14, 2015, two external computer hard drives were stolen from the covered entity's electrophysiology labs. The PHI included patients' names, dates of birth, unique identification numbers, and treatment information. Breached information was located on Other Portable Electronic Device. The CE improved physical access controls, eliminated the need for external hard drives, and notified HHS, affected individuals, and the media. OCR reviewed the risk assessment and confirmed corrective actions.
- VAHHS OCRas victim2014-01-16
Sentara Healthcare reported to HHS on 2014-01-16 a Theft, Unauthorized Access/Disclosure affecting 3891 individuals. Breached information located on Electronic Medical Record. Two former employees accessed PHI outside normal duties to process fraudulent tax returns.