Skip to content

AspenPointe

Disclosed Nov 19, 20205 years ago295,617 affectedConfirmed

Official notice

The covered entity (CE), AspenPointe, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 295,617 individuals. The PHI involved included names, dates of birth, Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE implemented additional technical and administrative safeguards to protect its PHI. OCR provided technical assistance to the CE regarding its HIPAA Privacy and Breach Notification Rule obligations.

What is known

People affected295,617 (as reported to HHS)
DisclosedNov 19, 2020
HappenedSep 12, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2020 data breach report: AspenPointein.gov · Official notice
HHS OCR breach report (archive, resolved): AspenPointe (Healthcare Provider, CO)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INNov 19, 20203
HHS archivetotalNov 19, 2020295,617
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 295617 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), AspenPointe, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 295,617 individuals. The PHI involved included names, dates of birth, Social Security numb · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about AspenPointe

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.