Centegra Health System
Disclosed Dec 1, 201510 years ago2,929 affectedConfirmed
The covered entity (CE), Centegra Health, reported that its business associate (BA) MedAssets accidentally mailed billing statements to the wrong recipients. This breach affected 2,929 individuals. The protected health information (PHI) involved included names, addresses, and claims information. The CE offered free credit monitoring services to all affected individuals. Following this breach incident, the BA implemented additional technical safeguards to better safeguard its PHI. The BA also revised its policies and procedures and retrained its staff. OCR obtained assurances that the BA implemented the corrective actions noted above.
What is known
| People affected | 2,929 (as reported to HHS) |
|---|---|
| Disclosed | Dec 1, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Centegra Health System (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 1, 2015 | 2,929 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.