Skip to content

Children's Hospital Colorado

Disclosed Jul 27, 20206 years ago2,553 affectedConfirmed

Official notice

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $548,265 civil monetary penalty against Children’s Hospital Colorado, concerning violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules following receipt of breach reports in 2017 and 2020, relating to email phishing and cyberattacks . OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates must follow to protect the privacy and security of protected health information (PHI). The HIPAA Security Rule establishes national standards to protect and secure our health care system by requiring administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic PHI (ePHI). “Email continues to be a very common way for cyberattackers to enter health information systems and jeopardized privacy and security,” said OCR Director Melanie Fontes Rainer. “Health care entities should identify potential risks and vulnera

What is known

People affected2,553 (as reported to HHS)
DisclosedJul 27, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 27, 20202,553

Other breaches at Children's Hospital Colorado

BreachAffected
Disclosed Sep 8, 2017Sep 8, 20179 years agoHacking3,370
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Children's Hospital Colorado

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.