Barnes-Jewish St. Peters Hospital
Disclosed Mar 12, 20188 years ago15,046 affectedConfirmed
Barnes-Jewish St. Peters Hospital, the covered entity (CE), reported that it discovered an error with how a data storage server was configured that made it possible for the electronic protected health information (ePHI) of 15,046 individuals to be accessible via the Internet. The ePHI involved included names, addresses, telephone numbers, dates of birth, Social Security numbers, drivers’ license numbers, health insurance information, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. Complimentary credit monitoring services were offered to affected individuals. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its ePHI. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 15,046 (as reported to HHS) |
|---|---|
| Disclosed | Mar 12, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Barnes-Jewish St. Peters Hospital (Healthcare Provider, MO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 12, 2018 | 15,046 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.