Back to the register

Baptist Health Louisville

ArchivedSubmitted 11/21/2017
State
KY
Covered entity type
Healthcare Provider
Individuals affected
880
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Baptist Health Louisville, the covered entity (CE), reported that two of its employees had been victims of a phishing incident on two separate days, exposing the protected health information (PHI), including names, dates of birth, addresses, social security numbers, and clinical information, of 880 individuals. The CE provided timely breach notification to HHS, affected individuals and the media. At the time of the breach and subsequently, the CE trained its employees on its HIPAA policies and procedures including the reporting of suspicious emails. In response to the breach, the CE specifically retrained the employees involved in the phishing incidents on identifying and reporting potential phishing emails. OCR reviewed the CE's HIPAA policies and procedures during the investigation and obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.
Baptist Health Louisville (KY), 11/21/2017 | InfoSec Signals