Arkansas Childrens Hospital
Disclosed Jun 28, 20188 years ago4,521 affectedConfirmed
Law enforcement notified the covered entity (CE) that a former workforce member fraudulently used patients’ Social Security numbers and other demographic information. The workforce member had access to 4,521 patients’ protected health information (PHI) to perform the essential functions of the job. Following the breach, the CE began revising its policy to incorporate a renewed background check of its workforce every three years. In addition, the CE implemented an access monitoring process which audits access to its patients' records and reports questionable recent activity and the date of activity, and provides a platform for documenting breach incident assessments and investigations. The CE provided breach notification to HHS, affected individuals, and the media and offered one year of free credit monitoring. OCR obtained assurances the CE implemented the corrective actions listed above.
What is known
| People affected | 4,521 (as reported to HHS) |
|---|---|
| Disclosed | Jun 28, 2018 |
| Happened | Nov 7, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2018 data breach report: Arkansas Childrens Hospitalin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Arkansas Children's Hospital (Healthcare Provider, AR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 28, 2018 | 3 |
| HHS archivetotal | Jun 29, 2018 | 4,521 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 4075 to 4521 · backfill source
- 2026-09-25 · summary: empty to Law enforcement notified the covered entity (CE) that a former workforce member fraudulently used patients’ Social Security numbers and other demographic information. The workforce member had access to 4,521 patients’ protected health infor · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.