Clay County Hospital
Disclosed Dec 12, 201411 years ago12,621 affectedConfirmed
On November 2, 2014, the covered entity’s (CE) president received an anonymous email threatening to release the protected health information (PHI) of hospital clinic patients to the public unless he or she received a substantial payment from the CE. This threat could have affected patients who visited the hospital on or before February 2012, approximately 12,621 individuals. The CE determined that the CE’s servers were not hacked nor were its information systems compromised. OCR determined that the voluntary corrective actions of the CE resolved this matter. Nonetheless, the CE provided breach notification to HHS, potentially affected individuals, and the media, and offered identity theft protection to the notified individuals. Additionally, the CE developed an encryption program and network auditing program. It re-trained staff on its newly implemented programs and its privacy and security policies. OCR obtained documented assurances that the CE implemented corrective action steps noted above..
What is known
| People affected | 12,621 (as reported to HHS) |
|---|---|
| Disclosed | Dec 12, 2014 |
| Happened | Nov 2, 2014 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2014 data breach report: Clay County Hospitalin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Clay County Hospital (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Dec 12, 2014 | 73 |
| HHS archivetotal | Dec 12, 2014 | 12,621 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 12621 · backfill source
- 2026-09-25 · summary: empty to On November 2, 2014, the covered entity’s (CE) president received an anonymous email threatening to release the protected health information (PHI) of hospital clinic patients to the public unless he or she received a substantial payment fro · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.