Back to the register

Healthgrades Operating Company, Inc.

ArchivedSubmitted 03/26/2021
State
GA
Covered entity type
Business Associate
Individuals affected
35,485
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The business associate (BA), Healthgrades Operating Company, reported that an employee was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of 35,485 individuals. The ePHI involved included names, addresses, dates of birth, Social Security numbers, clinical information, and health insurance information. The BA notified HHS and the covered entity notified affected individuals and the media. In response to the breach, the BA implemented a new email and security awareness program, implemented additional technical safeguards, and sanctioned and retrained the employee responsible for the breach.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.