Back to the register

Children's Mercy Hospital

ArchivedSubmitted 08/15/2014
State
MO
Covered entity type
Business Associate
Individuals affected
4,067
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Children's Mercy Hospital, reported that the protected health information (PHI) of 4,067 individuals stored in an online registration system by the subcontractor, Onsite Health Diagnostics, of its business associate (BA), StayWell Health Management, was hacked. The hacked information included names, encrypted passwords, email addresses, physical addresses, phone numbers, genders, and dates of birth. Because the subcontractor-generated passwords were encrypted/hashed, they were rendered unusable. The CE provided breach notification to HHS, affected individuals, and the media. The CE reported that the subcontractor moved all data from the affected scheduling application, moved all of its clients to a new scheduling platform, and completely decommissioned the vulnerable platform. The subcontractor also conducted a comprehensive security audit and found no other improper uses of protected health information or vulnerabilities. As a result of OCR's investigation, the CE provided documentation substantiating all actions taken.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.