Berry, Dunn, McNeil & Parker
Disclosed Sep 22, 20224 years ago2,068,426 affectedConfirmed
Berry, Dunn, McNeil, & Parker, the covered entity (CE) reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 2,068,426 individuals. The PHI involved included names, addresses, dates of birth, Social Security and drivers’ license numbers, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE offered free credit monitoring services and implemented additional administrative and technical safeguards to better protect PHI. The CE also terminated its business relationship with the BA.
What is known
| People affected | 2,068,426 (as reported to HHS) |
|---|---|
| Disclosed | Sep 22, 2022 |
| Discovered | Sep 14, 2023 |
| Happened | Sep 12, 2023 |
| Attack | Ransomware |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Berry, Dunn, McNeil & Parkeroag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: Berry, Dunn, McNeil & Parkeratg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Berry, Dunn, McNeil & Parkerjustice.oregon.gov · Official notice | Official notice |
| Vermont Attorney General: 2024-05-23 Berry, Dunn, McNeil & Parker Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| Indiana Attorney General 2024 data breach report: Berry Dunn McNeil & Parkerin.gov · Official notice | Official notice |
| Indiana Attorney General 2022 data breach report: Berry, Dunn, McNeil & Parkerin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Berry, Dunn, McNeil & Parker (Business Associate, ME)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Sep 22, 2022 | 3 |
| HHS archivetotal | Nov 21, 2023 | 2,068,426 |
| California AGresidents of CA | Apr 25, 2024 | |
| Washington AGresidents of WA | Apr 25, 2024 | 1,888 |
| Oregon DOJresidents of OR | Apr 25, 2024 | 1,107,354 |
| Indiana AGresidents of IN | Apr 25, 2024 | 5 |
| Vermont AGresidents of VT | May 23, 2024 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 10263 to 2068426 · backfill source
- 2026-09-25 · summary: empty to Berry, Dunn, McNeil, & Parker, the covered entity (CE) reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 2,068,426 individuals. The PHI involved included name · backfill source
- 2026-09-25 · records: 6395 to 10263 · backfill source
- 2026-09-25 · disclosed: 2024-04-25 to 2022-09-22 · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 6395 · backfill source
- 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-05-23-berry-dunn-mcneil-parker-data-breach-notice-consumers · backfill source
- 2026-09-25 · attack: unknown to ransomware · backfill source
- 2026-09-25 · discovered: empty to 2023-09-14 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.