Beacon Health Systems
Disclosed May 28, 20206 years ago900 affectedConfirmed
Beacon Health Systems, the covered entity (CE), reported that its business associate (BA) improperly disposed of documents containing the protected health information (PHI) of approximately 900 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, claims information, lab results, diagnoses, medications prescribed, and other clinical information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional administrative safeguards to better protect its PHI.
What is known
| People affected | 900 (as reported by the organization) |
|---|---|
| Disclosed | May 28, 2020 |
| Happened | Apr 1, 2020 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: Beacon Health Systemsin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Beacon Health systems (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | May 28, 2020 | 900 |
| HHS archivetotal | May 28, 2020 | 900 |
History of this record
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to Beacon Health Systems, the covered entity (CE), reported that its business associate (BA) improperly disposed of documents containing the protected health information (PHI) of approximately 900 individuals. The PHI involved included names, · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.