Skip to content

Centura Health

Disclosed Apr 22, 201412 years ago12,286 affectedConfirmed

Official notice

OCR initiated an investigation after the covered entity (CE), Centura Health, reported that it experienced a phishing attack. Because a few of its employees inadvertently responded to the fraudulent email by clicking on a link and providing their usernames and passwords, these employees’ email accounts may have been accessible to the attacker(s). The CE detected and contained the incident because less than 5% of its employees received the phishing email. The compromised email accounts resulted in a breach of 12,286 individuals’ electronic protected health information (ePHI) in the form of demographic (names, addresses, dates of birth, telephone numbers, social security numbers, other identifiers), clinical (diagnoses, lab results, medications, other treatment) and/or financial (claims) information. The CE provided breach notification to HHS, affected individuals, and the media. The CE also notified the Federal Bureau of Investigation and offered free credit monitoring services to the individuals who had their social security number or financial information potentially compromised. Following the breach, the CE updated its risk management plan which included escalating in priority it

What is known

People affected12,286 (as reported to HHS)
DisclosedApr 22, 2014
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Centura Health (Healthcare Provider, CO)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 22, 201412,286

Other breaches at Centura Health

BreachAffected
Disclosed Jun 12, 2021Jun 12, 20215 years agoHacking738
Disclosed May 22, 2019May 22, 20197 years agoHacking7,515
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Centura Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.