Skip to content

Associated Catholic Charities

Disclosed Jan 20, 20179 years ago1,145 affectedConfirmed

Official notice

Unauthorized users gained access to an employee’s email account after a phishing attack and automatically forwarded the employee’s emails to an external account. The breach included the protected health information (PHI) of 1,145 individuals and included names, addresses, dates of birth, social security numbers, and clinical information. Following the breach, the covered entity (CE), Associated Catholic Charities, added additional protection software to its email system and provided employees with additional security awareness training. Additionally, OCR reviewed the covered entity’s risk analysis to ensure compliance with the Security Rule. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected1,145 (as reported to HHS)
DisclosedJan 20, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 20, 20171,145
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Associated Catholic Charities

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.