Roswell Park Comprehensive Cancer Center
ent_fcfec860dd82504d8f10b209
Disclosures
4
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
149,126
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Roswell Park Comprehensive Cancer Center
- Normalized
- roswell park comprehensive cancer center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- roswellpark.org
Disclosure history (4)newest first
- NEW YORKHHS OCRas victim2025-02-24
Roswell Park Comprehensive Cancer Center (NY) reported to HHS OCR on 2025-02-24 a Theft incident affecting 11,435 individuals. Breached information was located on another portable electronic device. PHI involved included names, dates of birth, and clinical information. The CE notified HHS and affected individuals, and implemented additional administrative, technical, and security safeguards in response.
- NEW YORKHHS OCRas victim2024-02-14
Roswell Park Comprehensive Cancer Center (NY) reported to HHS on 2024-02-14 a Hacking/IT Incident affecting 755 individuals. Breached information was located in Email. PHI involved included names, medical record numbers, dates of birth, and health insurance and other treatment information. The CE notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards and retrained staff.
- NEW YORKHHS OCRas victim2020-09-14
Roswell Park Comprehensive Cancer Center reported to HHS on 2020-09-14 a Hacking/IT Incident affecting 149,126 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, emails, DOBs, and diagnoses. The CE notified HHS, individuals, and media.
- NEW YORKHHS OCRas victim2019-10-18
Roswell Park Comprehensive Cancer Center (NY) reported to HHS on 2019-10-18 an Unauthorized Access/Disclosure affecting 584 individuals. An employee impermissibly accessed ePHI stored in Electronic Medical Records, including names, birthdates, diagnoses, treatment information, and medications prescribed. The CE sanctioned the responsible employee, revised its policies and procedures, and OCR obtained assurances of corrective action. No business associate was involved.