Back to the register

Cummins Behavioral Health Systems

ArchivedSubmitted 04/12/2023
State
IN
Covered entity type
Healthcare Provider
Individuals affected
154,285
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Cummins Behavioral Health Systems, reported that it experienced a ransomware attack the affected the protected health information (PHI) of 154,285 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses/conditions, medications, and other treatment information. In response to the breach, the CE implemented additional administrative and technical safeguards. OCR provided the CE with technical assistance.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.