- State
- OR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 38,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 21, 2018, the covered entity (CE), Legacy Health, learned that an unauthorized third party may have gained access to some employees’ email accounts in May 2018, affecting approximately 38,000 individuals. The types of protected health information (PHI) involved in the breach included patients’ names, dates of birth, insurance information, billing information, driver's license numbers, Social Security numbers and medical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE began an investigation and engaged a law firm and other companies to assist. As a result of OCR’s investigation, the CE implemented enhanced email security protections, implemented multi-factor authentication for all users on all of its systems, and enhanced malware defenses on its firewall.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.