Skip to content

Mass General Brigham

Disclosed Jun 28, 20242 years ago655 affectedConfirmed

Official notice

Mass General Brigham, the covered entity (CE), reported that several employees impermissibly shared their system credentials with an unauthorized individual in an effort to outsource their job duties. This breach affected the protected health information (PHI) of 655 individuals. The PHI involved included names, addresses, medical record numbers, dates of birth, email addresses, phone numbers, Social Security numbers, health insurance and claims information, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and established a call center for questions or concerns. In addition, the employees were sanctioned and all staff were retrained on the requirement to protect and secure sensitive data.

What is known

People affected655 (as reported to HHS)
DisclosedJun 28, 2024
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mass General Brigham (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJun 28, 2024655

Other breaches at Mass General Brigham

BreachAffected
Disclosed Dec 18, 2020Dec 18, 20205 years ago32K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mass General Brigham

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.