- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 12,286
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR initiated an investigation after the covered entity (CE), Centura Health, reported that it experienced a phishing attack. Because a few of its employees inadvertently responded to the fraudulent email by clicking on a link and providing their usernames and passwords, these employees’ email accounts may have been accessible to the attacker(s). The CE detected and contained the incident because less than 5% of its employees received the phishing email. The compromised email accounts resulted in a breach of 12,286 individuals’ electronic protected health information (ePHI) in the form of demographic (names, addresses, dates of birth, telephone numbers, social security numbers, other identifiers), clinical (diagnoses, lab results, medications, other treatment) and/or financial (claims) information. The CE provided breach notification to HHS, affected individuals, and the media. The CE also notified the Federal Bureau of Investigation and offered free credit monitoring services to the individuals who had their social security number or financial information potentially compromised. Following the breach, the CE updated its risk management plan which included escalating in priority its implementation of certain previously identified security measures; retrained all its employees, and enhanced its annual compliance education training to provide additional content regarding phishing scams. OCR obtained assurance that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.