- State
- WI
- Covered entity type
- Healthcare Provider
- Individuals affected
- 19,150
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Wisconsin Department of Health Services, reported that its business associate (BA) experienced a cyberattack that compromised the protected health information (PHI) of 19,150 individuals. The PHI involved included names, dates of birth, social security numbers, diagnoses/conditions, and other treatment information. The CE notified HHS and the media; the BA notified the affected individuals. In its mitigation efforts, the CE provided credit monitoring and established a call center for questions and concerns. The BA implemented additional administrative and technical safeguards to better protect sensitive data.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.