Skip to content

Beacon Health System

Disclosed May 26, 20179 years ago1,239 affectedConfirmed

Official notice

Beginning on or around March 1, 2014, an employee of the covered entity (CE), Beacon Health System, impermissibly accessed Emergency Room (ER) patient records while working in the billing department. The employee had access to protected health information (PHI) for 1,239 ER patients, including addresses, dates of birth, names, social security numbers, ages, room numbers, claims information, billing, accounts, invoices, health insurance, illness, and chief complaint. The CE provided breach notification to HHS, affected individuals and the media. It also provided credit monitoring to affected individuals. Following the breach, the CE sanctioned the employee in accordance with its sanction policy. During our investigation, we found that a large number of the CE's staff either did not complete HIPAA training or only completed a portion of the training for 2016. OCR requested that the CE update its HIPAA training policy and audit policy. In response, the CE provided OCR with documentation of actions it took, including redrafting its HIPAA training policy, updating its audit policy and providing evidence of daily audits and log runs.

What is known

People affected1,239 (as reported to HHS)
DisclosedMay 26, 2017
HappenedApr 17, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMay 26, 20171,239
Indiana AGresidents of INAug 6, 2019319

Other breaches at Beacon Health System

BreachAffected
Disclosed Mar 10, 2023Mar 10, 20233 years agoInsider3,304
Disclosed Aug 7, 2020Aug 7, 20206 years ago25
Disclosed Jun 1, 2018Jun 1, 20188 years ago141
Phishing attack on staff email exposes data of 306,789 Indiana patientsMay 22, 201511 years agoPhishing307K
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 364 to 1239 · backfill source
  • 2026-09-25 · disclosed: 2019-08-06 to 2017-05-26 · backfill source
  • 2026-09-25 · summary: empty to Beginning on or around March 1, 2014, an employee of the covered entity (CE), Beacon Health System, impermissibly accessed Emergency Room (ER) patient records while working in the billing department. The employee had access to protected hea · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Beacon Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.