Green Ridge Behavioral Health
ent_fb65666228353f9d8ba7524c
Disclosures
2
HHS OCR enforcement · HHS OCR · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
14,000
nationwide · HHS OCR MD
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Green Ridge Behavioral Health
- Normalized
- green ridge behavioral health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- greenridgebh.com
Disclosure history (2)newest first
- FEDERALHHS OCR enforcementas victim2023-10-30
HHS OCR settled with Green Ridge Behavioral Health, LLC (GRBH) for $40,000 regarding a 2019 ransomware attack that exposed over 14,000 patients' PHI. GRBH failed to conduct risk analyses, implement security measures, review audit logs, and comply with privacy rules. The resolution agreement includes a Corrective Action Plan requiring comprehensive risk analysis, risk management, policy updates, workforce training, and business associate agreement reviews.
- MARYLANDHHS OCRas victim2019-02-11
Green Ridge Behavioral Health, LLC reported to HHS on 2019-02-11 a Hacking/IT Incident affecting 14000 individuals. Breached information located on Electronic Medical Record, Network Server. The incident involved a ransomware attack encrypting patient electronic health records. HHS OCR reached a settlement requiring a $40,000 payment and a three-year corrective action plan.