- State
- OK
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,278
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 9 and 22, 2015, Aspire Home Care and Hospice, the covered entity (CE), experienced two similar breach incidents. The breach incidents involved phishing scams on the Google email accounts of two CE employees. The type of protected health information (PHI) involved in the breaches included demographic information, social security numbers, and treatment information. One breach report estimated that 4,278 individuals were affected, and in the second the estimate was 4,500 individuals. Later that number was amended since the CE determined that 1,889 persons had already been accounted for in the initial breach report. In response to the breach incidents, the CE took certain corrective action, including, but not limited to, implementing additional technical safeguards to prevent future security incidents of this nature. As a result of extensive technical assistance provided by OCR, the CE took corrective action, launching a phishing campaign to better train and educate workforce members regarding potential phishing incidents, and implementing additional Privacy and Security policies and procedures to ensure full compliance with the Privacy and Security Rules. Further, the CE conducted an updated risk analysis and implemented a corresponding risk management plan. The CE also offered affected individuals identity theft monitoring services for one year at no cost.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.