Massachusetts General Hospital
ent_fdfd7a3b52b6835792ff1436
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
4,293
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Massachusetts General Hospital
- Normalized
- massachusetts general hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- massgeneral.org
Disclosure history (5)newest first
- 🍁Vermont State AGas victim2024-02-21
Massachusetts General Hospital filed a data breach notice with the Vermont Attorney General on February 21, 2024. The notice advises consumers to review account statements and update personal information. The specific nature of the breach, data types compromised, and number of affected individuals are not detailed in the filing page itself, though the attached PDF is a consumer notice regarding protected health information.
- ⛰️New Hampshire State AGas victim2023-12-08
New Hampshire Attorney General's office received a breach notification from Massachusetts General Hospital and Mass General Brigham Incorporated on December 8, 2023. The provided source document is empty; no details regarding the incident nature, affected data, or individual count are available in the text.
- MASSACHUSETTSHHS OCRas victim2018-12-14
Massachusetts General Hospital reported to HHS on 2018-12-14 an Unauthorized Access/Disclosure affecting 588 individuals. Breached information located on Paper/Films. A business associate erroneously sent retirement-notification letters to 580 patients with the wrong patient names due to a mail merge error, exposing PHI (patient names and treating physician identity). The CE notified affected individuals, retrained staff, terminated the BA relationship, and internalized mailings. OCR obtained corrective-action assurances.
- FEDERALHHS OCRas victim2016-06-29
Hackers caused a breach of protected health information (PHI) at Patterson Dental Supply, Inc., a business associate (BA) of the covered entity (CE), Massachusetts General Hospital. The breach affected the PHI of approximately 4,293 individuals, and included demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. OCR’s investigation revealed that the CE and BA had a business associate agreement in place at the time of the breach. OCR has opened a separate review of the BA concerning the underlying breach.
- MASSACHUSETTSHHS OCRas victim2015-07-08
Massachusetts General Hospital reported to HHS OCR on 2015-07-08 an Unauthorized Access/Disclosure affecting 648 individuals. An employee sent an unencrypted email containing PHI (names, dates of birth, medical record numbers, and Social Security numbers) to an incorrect email address. The employee was sanctioned and the CE updated its policy to use a secure storage application in place of email for PHI transmission. OCR obtained assurances of corrective action implementation.