Skip to content

Children's Heart Center

Disclosed Apr 3, 201511 years ago8,791 affectedConfirmed

Official notice

An employee was arrested on-site for suspicion of identity theft after using electronic protected health information (ePHI) obtained while employed by the covered entity (CE) to open a credit card account in another individual’s name. The employee had a criminal history which was not identified during the CE’s hiring process. The CE provided breach notification to HHS, affect individuals, and the media. It also cooperated with the subsequent law enforcement investigation. Following the breach, the CE sanctioned the employee and terminated and replaced its vendor for background checks of potential employees. The CE also improved its physical security, enhanced technical safeguards for ePHI, formed a committee to formalize written policies for safeguarding ePHI, and enhanced staff training. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected8,791 (as reported by the organization)
DisclosedApr 3, 2015
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INApr 3, 20151
HHS archivetotalApr 3, 20158,791
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to An employee was arrested on-site for suspicion of identity theft after using electronic protected health information (ePHI) obtained while employed by the covered entity (CE) to open a credit card account in another individual’s name. The e · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Children's Heart Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.