Skip to content

Ardon Health

Disclosed Nov 22, 20241 year ago10,098 affectedConfirmed

Official notice

The covered entity (CE), Ardon Health, LLC, reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 10,098 individuals. The PHI involved included names, addresses, medications, birthdates, and treatment information. The CE notified HHS, affected individuals and the media. In response to the breach and OCR’s investigation, the CE has updated its technical safeguards. OCR also provided technical assistance to the CE regarding the HIPAA Security Rule.

What is known

People affected10,098 (as reported to HHS)
DisclosedNov 22, 2024
DiscoveredSep 27, 2024
HappenedSep 9, 2024
AttackPhishing
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Washington Attorney General breach notice: Ardon Healthatg.wa.gov · Official notice
Oregon DOJ breach notice: Ardon Healthjustice.oregon.gov · Official notice
HHS OCR breach report (archive, resolved): Ardon Health (Healthcare Provider, OR)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Washington AGresidents of WANov 22, 20246,527
Oregon DOJresidents of ORNov 22, 202410,098
HHS archivetotalNov 22, 202410,098
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 10098 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Ardon Health, LLC, reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 10,098 individuals. The PHI involved included names, addresses · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.

Everything about Ardon Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.