City of San Luis
Disclosed Jun 20, 20233 years ago6,848 affectedConfirmed
The covered entity (CE), City of San Luis, reported that an employee was subject to an email phishing scheme that affected the protected health information (PHI) of 6,848 individuals. The PHI involved included names, addresses, drivers’ license numbers, dates of birth, Social Security numbers, claims information, medications, and diagnoses. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
What is known
| People affected | 6,848 (as reported by the organization) |
|---|---|
| Disclosed | Jun 20, 2023 |
| Happened | Feb 1, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Government · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2023 data breach report: City of San Luisin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): City of San Luis (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 20, 2023 | 6,848 |
| Indiana AGresidents of IN | Oct 27, 2023 | 1 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · disclosed: 2023-10-27 to 2023-06-20 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), City of San Luis, reported that an employee was subject to an email phishing scheme that affected the protected health information (PHI) of 6,848 individuals. The PHI involved included names, addresses, drivers’ lic · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.