- State
- PA
- Covered entity type
- Business Associate
- Individuals affected
- 1,692
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized user gained access to employees’ email account after a phishing attack. The breach included the protected health information (PHI) of 1,692 individuals including patients’ names, dates of birth, social security numbers, claims information, clinical information, and financial information. Following the breach, the covered entity upgraded its email encryption software, implemented multi-factor authentication for its email accounts, and trained employees on phishing emails and cyber threats. Additionally, OCR provided technical assistance on timely breach notifications.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.