Skip to content

Childrens Mercy Hospital

Disclosed May 19, 20179 years ago65,930 affectedConfirmed

Official notice

The covered entity (CE), Children’s Mercy Hospital, reported that a hacker used a software-defined radio (SDR) or similar data capture device to intercept protected health information (PHI) transmitted via the CE’s pager system. The breach affected the PHI of 1,463 individuals and included names, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards and retrained its workforce members.

What is known

People affected65,930 (as reported to HHS)
DisclosedMay 19, 2017
HappenedDec 2, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMay 19, 20175,511
Indiana AGresidents of INJan 31, 201817
HHS archivetotalJan 31, 201865,930
HHS archivetotalJun 27, 20181,463

Other breaches at Childrens Mercy Hospital

BreachAffected
Disclosed Aug 15, 2014Aug 15, 201412 years agoHacking4,067
History of this record
  • 2026-09-25 · disclosed: 2018-01-31 to 2017-05-19 · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 38873 to 65930 · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Children’s Mercy Hospital, reported that a hacker used a software-defined radio (SDR) or similar data capture device to intercept protected health information (PHI) transmitted via the CE’s pager system. The breach · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Childrens Mercy Hospital

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.