CareSTL Health
Disclosed Oct 3, 202511 months ago501 affectedConfirmed
The covered entity (CE), CareSTL Health, reported that it experienced a ransomware attack that compromised the protected health information (PHI) of 501 individuals. The PHI involved clinical and demographic information. In its mitigation efforts, the CE revised its policies and procedure regarding the HIPAA Privacy and Security Rules, trained or retrained its workforce, and mailed notification letters to all affected individuals. OCR provided technical assistance to the CE.
What is known
| People affected | 501 (as reported to HHS) |
|---|---|
| Disclosed | Oct 3, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): CareSTL Health (Healthcare Provider, MO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 3, 2025 | 501 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.