Conway Regional Health System
ent_fd96b463e00a35539dbc3bdf
Disclosures
3
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
37,000
as filed · HHS OCR AR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Conway Regional Health System
- Normalized
- conway regional health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- ARHHS OCRas victim2020-11-06
Conway Regional Health System reported to HHS on 2020-11-06 a Unauthorized Access/Disclosure affecting 2945 individuals. Breached information located on Email. Employees were victims of an email phishing attack exposing PHI including names, DOB, email, MRNs, and lab results.
- ARHHS OCRas victim2019-08-23
Conway Regional Health System (Conway, AR) reported to HHS OCR on 2019-08-23 a Hacking/IT Incident affecting approximately 37,000 individuals via an email phishing scheme. Exposed ePHI included names, addresses, medications prescribed, health insurance information, and Social Security numbers. The CE notified HHS, affected individuals, and the media, and offered complimentary credit monitoring. OCR obtained assurances that corrective actions — including improved email technical safeguards — were implemented.
- FEDERALHHS OCRas victim2011-10-21
Conway Regional Medical Center reported to HHS on 2011-10-21 a loss of two compact disks affecting 1,472 individuals. The disks, sent by a business associate, contained protected health information including demographic and financial data, and were mislaid after receipt. The medical center has since updated its policies, retrained staff, and improved safeguards for handling patient information.