Skip to content

Baptist Health Louisville

Disclosed Nov 21, 20178 years ago880 affectedConfirmed

Official notice

Baptist Health Louisville, the covered entity (CE), reported that two of its employees had been victims of a phishing incident on two separate days, exposing the protected health information (PHI), including names, dates of birth, addresses, social security numbers, and clinical information, of 880 individuals. The CE provided timely breach notification to HHS, affected individuals and the media. At the time of the breach and subsequently, the CE trained its employees on its HIPAA policies and procedures including the reporting of suspicious emails. In response to the breach, the CE specifically retrained the employees involved in the phishing incidents on identifying and reporting potential phishing emails. OCR reviewed the CE's HIPAA policies and procedures during the investigation and obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected880 (as reported to HHS)
DisclosedNov 21, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 21, 2017880

Other breaches at Baptist Health Louisville

BreachAffected
Disclosed Feb 26, 2016Feb 26, 201610 years ago140
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Baptist Health Louisville

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.