Holy Cross Hospital, Inc.
ent_faf68ffa2a31f85226381628
Disclosures
2
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
9,900
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Holy Cross Hospital, Inc.
- Normalized
- holy cross hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- FEDERALHHS OCRas victim2013-09-24
An employee of Holy Cross Hospital, Inc. accessed and used protected health information (PHI) outside of their job duties to file fraudulent tax returns. The breach, reported to HHS on September 24, 2013, affected 9,900 individuals and compromised names, addresses, and Social Security numbers. The information was located on a desktop computer and network server. In response, the hospital terminated the employee, retrained staff, and enhanced its risk management procedures.
- FLHHS OCRas victim2010-11-16
Holy Cross Hospital (FL) reported to HHS OCR on 2010-11-16 a Theft/insider incident affecting 1,500 individuals (notification sent to ~44,000 potentially affected). A hospital employee impermissibly copied patient data sheets containing PHI — including names, addresses, dates of birth, SSNs, insurance information, and diagnoses — and sold the information to a third party. Confirmed PHI of 38 individuals was sold; ~1,500 were initially identified as at risk. The CE cooperated with federal and state authorities, offered free credit monitoring, and implemented extensive corrective actions under OCR oversight.