Back to the register

Legacy Health

ArchivedSubmitted 08/20/2018
State
OR
Covered entity type
Healthcare Provider
Individuals affected
38,000
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On June 21, 2018, the covered entity (CE), Legacy Health, learned that an unauthorized third party may have gained access to some employees’ email accounts in May 2018, affecting approximately 38,000 individuals. The types of protected health information (PHI) involved in the breach included patients’ names, dates of birth, insurance information, billing information, driver's license numbers, Social Security numbers and medical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE began an investigation and engaged a law firm and other companies to assist. As a result of OCR’s investigation, the CE implemented enhanced email security protections, implemented multi-factor authentication for all users on all of its systems, and enhanced malware defenses on its firewall.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.