- State
- IN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 660
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Computer servers of Goshen Health System’s business associate (BA), Silver Tech, may have been injected with a virus on December 22, 2011. The BA operates a consumer website on behalf of the covered entity (CE) for employment and pre-registration for screenings and diagnostic testing. The BA’s servers contained the electronic protected health information (ePHI) of approximately 660 individuals, including patients’ names, social security numbers, addresses, insurance carriers, and testing information, and financial information. The CE provided breach notification to HHS, affected individuals, the media. It also notified the Indiana Attorney General’s office and the FBI and offered one year of free credit monitoring services to affected individuals. Following the breach, the CE terminated its relationship with the BA, engaged an outside forensic security firm to conduct an internal investigation, and updated its website. The CE revised its HIPAA policies and procedures and updated its practices to ensure the proper execution of Business Associate Agreements with all vendors and other parties who may have access to PHI. The CE trained its employees on its policies and procedures and documented its most recent risk analysis and corresponding risk management plan. OCR obtained documentation evidencing that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.