Itrcbreachreport2015
Total Page:16
File Type:pdf, Size:1020Kb
Identity Theft Resource Center 2015 Breach List: Breaches: 780 Exposed: 177,866,236 How is this report produced? What are the rules? See last page of report for details. Report Date: 12/29/2015 Page 1 of 169 ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-07 SAS Safety Corporation CA 12/24/2015 Electronic Business Yes - Unknown # Unknown Based upon the Company's investigation, the maiware was present from September 23, 2015 to December 8, 2013 and potentially exposed certain personal information of one resident that was inputted by that customer. The personal information that was potentially affected by the incident includes: customer name, address, credit or debit card number, payment card expiration date and the card's CVV security number. Additionally, the customer's logon identification and password for the website may have been affected. The Company does not collect customers' social security or driver's license numbers and that data was in no way affected by the incident. Attribution 1 Publication: NH AG's office Author: Article Title: SAS Safety Corporation Article URL: http://doj.nh.gov/consumer/security-breaches/documents/sas-safety-20151224.pdf ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-06 AllMed / Central Alabama AL 12/21/2015 Electronic Medical/Healthcare Yes - Unknown # Unknown Primary Care Specialists Medical records were found Monday in an open air dumpster behind a former medical clinic called AllMed on Eastchase Parkway near Minnie Brown Road in east Montgomery. The records included prescriptions, lab results, names of patients and their birthdays -- all considered Private Health Information under HIPAA privacy laws. Attribution 1 Publication: WTVM. Com / databreaches.net Author: Article Title: Medical records found in dumpster in east Montgomery Article URL: http://www.wtvm.com/story/30804533/exposed-medical-records-found-in-dumpster-in-east-montgomery ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-05 Cottonwood Comfort Dental NM 12/26/2015 Paper Data Medical/Healthcare Yes - Unknown # Unknown An Albuquerque man said he found hundreds of medical records dumped on the West Mesa. The medical records include people’s addresses, insurance information and social security numbers. Attribution 1 Publication: databreaches.net / KRQE Author: Article Title: New Mexican dental patients’ records found dumped along West Mesa Article URL: http://www.databreaches.net/new-mexican-dental-patients-records-found-dumped-along-west-mesa/ ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-04 Oregon Department of OR 12/29/2015 Paper Data Government/Military Yes - Published # 967 Veterans' Affairs The Oregon Department of Veterans’ Affairs says the personal information of hundreds of veterans may have been compromised. Attribution 1 Publication: databreaches.net Author: Article Title: Personal Info On Hundreds Of Oregon Veterans Compromised Article URL: http://www.databreaches.net/personal-info-on-hundreds-of-oregon-veterans-compromised/ ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-03 Quincy Credit Union MA 12/29/2015 Electronic Banking/Credit/Financial Yes - Unknown # Unknown Authorities continue to investigate a security breach at the Quincy Credit Union, a breach that gave hackers access to hundreds of accounts. Attribution 1 Publication: BostonCBSLocal.com / databreaches.ne Author: Jim Smith Article Title: Security Breach At Quincy Credit Union Investigated Article URL: http://boston.cbslocal.com/2015/12/28/security-breach-at-quincy-credit-union-investigated/ Copyright 2015 Identity Theft Resource Center Identity Theft Resource Center 2015 Breach List: Breaches: 780 Exposed: 177,866,236 How is this report produced? What are the rules? See last page of report for details. Report Date: 12/29/2015 Page 2 of 169 ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-02 Home Delivery Incontinence MO 12/28/2015 Electronic Medical/Healthcare Yes - Unknown # Unknown Supplies We began investigating the incident immediately upon learning of it on November 30, 2015. Based upon our investigation, it appears the incident occurred when harmful computer code, known as "malware," was inserted onto the shopping cart checkout software on our website without our authorization and despite the security features we have in place. This malware may have accessed customer information as it was input by customers during the checkout process. Attribution 1 Publication: VTAG's office Author: Article Title: Home Delivery Incontinence Supplies Article URL: http://ago.vermont.gov/assets/files/Consumer/Security_Breach/HDIS%20SBN%20to%20Consumers.pdf ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151229-01 Washington Township Health WA 10/8/2015 Electronic Medical/Healthcare Yes - Unknown # Unknown Care District Breach posted on AG website with no breach notification letter. Attribution 1 Publication: CA AG's Office Author: Article Title: Washington Township Health Care District Article URL: https://oag.ca.gov/ecrime/databreach/reports/sb24-59419 ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151228-07 Belgrade Regional Health ME 12/18/2015 Paper Data Medical/Healthcare Yes - Published # 854 Center A physician’s assistant leaving the Belgrade Regional Health Center warranted a letter being sent to patients to tell them about the impending change in personnel; however, that letter also resulted in a breach of 854 patients’ Protected Health Information (PHI). The mailing took place on October 21, 2015 and patients first started notifying the health center of the error two days later when the letters started to be received. Attribution 1 Publication: hhs.gov / hipaajournal.com Author: Article Title: Belgrade Regional Health Center Article URL: http://www.hipaajournal.com/mailing-error-results-in-phi-exposure-of-belgrade-regional-health-center-patients-8238/ ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151228-06 Physicians Health Plan of IN 12/24/2015 Paper Data Medical/Healthcare Yes - Published # 1,708 Northern Indiana Physicians Health Plan of Northern Indiana has alerted some of its Indigo members about a breach of a limited amount of their Protected Health Information (PHI) after an error was made mailing their billing statements. The breach involved multiple billing statements being sent on December 8, 2015, some of which were intended for other health plan subscribers. The mistake has been attributed to human error. Attribution 1 Publication: hipaajournal.com / databreaches.net Author: Article Title: MAILING ERROR EXPOSES PHI OF PHP HEALTH PLAN SUBSCRIBERS Article URL: http://www.hipaajournal.com/mailing-error-exposes-phi-of-php-health-plan-subscribers-8236/ ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151228-05 Voter Registration Database US 12/28/2015 Electronic Business Yes - Unknown # Unknown Researcher Chris Vickery, who this month found myriad databases left open to all and sundry, told FORBES he has his hands on all 300GB of voter data, which includes names, home addresses, phone numbers, dates of birth, party affiliations, and logs of whether or not they had voted in primary or general elections. The data appears to date back to 2000. It does not contain financial data or social security numbers. Attribution 1 Publication: Forbes.com Author: Article Title: 191 Million US Voter Registration Records Leaked In Mystery Database Article URL: http://www.forbes.com/sites/thomasbrewster/2015/12/28/us-voter-database-leak/ Copyright 2015 Identity Theft Resource Center Identity Theft Resource Center 2015 Breach List: Breaches: 780 Exposed: 177,866,236 How is this report produced? What are the rules? See last page of report for details. Report Date: 12/29/2015 Page 3 of 169 ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151228-04 HealthSouth Rehabilitation TX 12/23/2015 Electronic Medical/Healthcare Yes - Published # 1,359 Hospital of Round Rock HealthSouth Rehabilitation Hospital of Round Rock (Texas) is notifying individuals that some medical and personal information may have been lost when an employee's laptop was stolen. Attribution 1 Publication: HealthSouth Hospital of Round Rock we Author: Article Title: Rehabilitation Hospital in Round Rock Notifies Individuals of Possible Theft of Health Data Article URL: http://www.healthsouthroundrock.com/en/news-listing/2015-data-breach ITRC Breach ID Company or Agency State Published Date Breach Type Breach Category Records Exposed? Records Reported ITRC20151228-03 Hyatt Hotels IL 12/27/2015 Electronic Business Yes - Unknown # Unknown Hyatt Hotels recently detected malware on the computer system that processes payments for its hotels, The Guardian reports. It's not clear at this point whether any customer data was actually stolen, how long the malware was present