Holy Cross Hospital, Inc.
ent_faf68ffa2a31f85226381628
Disclosures
7
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
9,900
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Holy Cross Hospital, Inc.
- Normalized
- holy cross hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Illinois State AGas victim2020-01-01
HOLY CROSS HOSPITAL filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-433). The register records the breach as discovered on June 24, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2020-01-01
HOLY CROSS HOSPITAL filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-432). The register records the breach as discovered on June 24, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2014-09-10
Holy Cross Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-09-10. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2013-10-15
Holy Cross Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-10-15. 7 Massachusetts residents were affected. The report records the breach type as electronic.
- FLORIDAHHS OCRas victim2013-09-24
An employee of Holy Cross Hospital, Inc. accessed and used protected health information (PHI) outside of their job duties to file fraudulent tax returns. The breach, reported to HHS on September 24, 2013, affected 9,900 individuals and compromised names, addresses, and Social Security numbers. The information was located on a desktop computer and network server. In response, the hospital terminated the employee, retrained staff, and enhanced its risk management procedures.
- Massachusetts State AGas victim2010-11-22
Holy Cross Hospital reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-11-22. 278 Massachusetts residents were affected. The report records the breach type as paper.
- FLORIDAHHS OCRas victim2010-11-16
Holy Cross Hospital (FL) reported to HHS OCR on 2010-11-16 a Theft/insider incident affecting 1,500 individuals (notification sent to ~44,000 potentially affected). A hospital employee impermissibly copied patient data sheets containing PHI — including names, addresses, dates of birth, SSNs, insurance information, and diagnoses — and sold the information to a third party. Confirmed PHI of 38 individuals was sold; ~1,500 were initially identified as at risk. The CE cooperated with federal and state authorities, offered free credit monitoring, and implemented extensive corrective actions under OCR oversight.