Skip to content

Centegra Health System

Disclosed Dec 1, 201510 years ago2,929 affectedConfirmed

Official notice

The covered entity (CE), Centegra Health, reported that its business associate (BA) MedAssets accidentally mailed billing statements to the wrong recipients. This breach affected 2,929 individuals. The protected health information (PHI) involved included names, addresses, and claims information. The CE offered free credit monitoring services to all affected individuals. Following this breach incident, the BA implemented additional technical safeguards to better safeguard its PHI. The BA also revised its policies and procedures and retrained its staff. OCR obtained assurances that the BA implemented the corrective actions noted above.

What is known

People affected2,929 (as reported to HHS)
DisclosedDec 1, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Centegra Health System (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 1, 20152,929
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Centegra Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.