Associated Catholic Charities
Disclosed Jan 20, 20179 years ago1,145 affectedConfirmed
Unauthorized users gained access to an employee’s email account after a phishing attack and automatically forwarded the employee’s emails to an external account. The breach included the protected health information (PHI) of 1,145 individuals and included names, addresses, dates of birth, social security numbers, and clinical information. Following the breach, the covered entity (CE), Associated Catholic Charities, added additional protection software to its email system and provided employees with additional security awareness training. Additionally, OCR reviewed the covered entity’s risk analysis to ensure compliance with the Security Rule. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,145 (as reported to HHS) |
|---|---|
| Disclosed | Jan 20, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Associated Catholic Charities (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 20, 2017 | 1,145 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.