- State
- IL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 12,621
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On November 2, 2014, the covered entity’s (CE) president received an anonymous email threatening to release the protected health information (PHI) of hospital clinic patients to the public unless he or she received a substantial payment from the CE. This threat could have affected patients who visited the hospital on or before February 2012, approximately 12,621 individuals. The CE determined that the CE’s servers were not hacked nor were its information systems compromised. OCR determined that the voluntary corrective actions of the CE resolved this matter. Nonetheless, the CE provided breach notification to HHS, potentially affected individuals, and the media, and offered identity theft protection to the notified individuals. Additionally, the CE developed an encryption program and network auditing program. It re-trained staff on its newly implemented programs and its privacy and security policies. OCR obtained documented assurances that the CE implemented corrective action steps noted above..
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.