Skip to content

Berry, Dunn, McNeil & Parker

Disclosed Sep 22, 20224 years ago2,068,426 affectedConfirmed

Official notice

Berry, Dunn, McNeil, & Parker, the covered entity (CE) reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 2,068,426 individuals. The PHI involved included names, addresses, dates of birth, Social Security and drivers’ license numbers, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative and technical safeguards to better protect PHI. The CE also terminated its business relationship with the BA.

What is known

People affected2,068,426 (as reported to HHS)
DisclosedSep 22, 2022
DiscoveredSep 14, 2023
HappenedSep 12, 2023
AttackRansomware
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INSep 22, 20223
HHS archivetotalNov 21, 20232,068,426
California AGresidents of CAApr 25, 2024
Washington AGresidents of WAApr 25, 20241,888
Oregon DOJresidents of ORApr 25, 20241,107,354
Indiana AGresidents of INApr 25, 20245
Vermont AGresidents of VTMay 23, 2024
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 10263 to 2068426 · backfill source
  • 2026-09-25 · summary: empty to Berry, Dunn, McNeil, & Parker, the covered entity (CE) reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 2,068,426 individuals. The PHI involved included name · backfill source
  • 2026-09-25 · records: 6395 to 10263 · backfill source
  • 2026-09-25 · disclosed: 2024-04-25 to 2022-09-22 · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 6395 · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-05-23-berry-dunn-mcneil-parker-data-breach-notice-consumers · backfill source
  • 2026-09-25 · attack: unknown to ransomware · backfill source
  • 2026-09-25 · discovered: empty to 2023-09-14 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Berry, Dunn, McNeil & Parker

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.