Aspire Home Care and Hospice
Disclosed Oct 9, 201510 years ago4,278 affectedConfirmed
On October 9 and 22, 2015, Aspire Home Care and Hospice, the covered entity (CE), experienced two similar breach incidents. The breach incidents involved phishing scams on the Google email accounts of two CE employees. The type of protected health information (PHI) involved in the breaches included demographic information, social security numbers, and treatment information. One breach report estimated that 4,278 individuals were affected, and in the second the estimate was 4,500 individuals. Later that number was amended since the CE determined that 1,889 persons had already been accounted for in the initial breach report. In response to the breach incidents, the CE took certain corrective action, including, but not limited to, implementing additional technical safeguards to prevent future security incidents of this nature. As a result of extensive technical assistance provided by OCR, the CE took corrective action, launching a phishing campaign to better train and educate workforce members regarding potential phishing incidents, and implementing additional Privacy and Security policies and procedures to ensure full compliance with the Privacy and Security Rules. Further, the CE co
What is known
| People affected | 4,278 (as reported to HHS) |
|---|---|
| Disclosed | Oct 9, 2015 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Aspire Home Care and Hospice (Healthcare Provider, OK)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 9, 2015 | 4,278 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.