Aegis Medical Group
Disclosed Nov 7, 20196 years ago9,800 affectedConfirmed
Aegis Medical Group, the covered entity (CE), reported than an employee was using its patients’ protected health information (PHI) for nefarious purposes. This breach affected 8,454 individuals and the PHI involved included names, dates of birth, addresses, drivers’ license information, Social Security numbers, clinical information, health insurance information, diagnoses/conditions, lab results, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE sanctioned the employee, implemented additional administrative safeguards, and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 9,800 (as reported by the organization) |
|---|---|
| Disclosed | Nov 7, 2019 |
| Discovered | Sep 11, 2019 |
| Happened | Jul 24, 2019 |
| Attack | Insider |
| Data exposed | Names, Social Security numbers, Government IDs, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2019 data breach report: Aegis Medical Groupin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Aegis Medical Groupmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Aegis Medical Group (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 7, 2019 | 9,800 |
| Indiana AGresidents of IN | Nov 8, 2019 | 5 |
| Maine AGresidents of ME | Nov 8, 2019 | 4 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: ["names","ssn","government-id"] to ["names","ssn","government-id","health"] · backfill source
- 2026-09-25 · disclosed: 2019-11-08 to 2019-11-07 · backfill source
- 2026-09-25 · summary: empty to Aegis Medical Group, the covered entity (CE), reported than an employee was using its patients’ protected health information (PHI) for nefarious purposes. This breach affected 8,454 individuals and the PHI involved included names, dates of · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn","government-id"] · backfill source
- 2026-09-25 · discovered: empty to 2019-09-11 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.