Compass Behavioral Health
Disclosed Feb 10, 20233 years ago537 affectedConfirmed
The covered entity (CE), Compass Behavioral Health, reported that several employees were the targets of an email phishing attack that affected the protected health information (PHI) of 537 individual. The PHI involved included names, addresses, dates of birth, and diagnoses/conditions. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE implemented additional administrative and technical security safeguards, and retrained its workforce members. OCR provided technical assistance.
What is known
| People affected | 537 (as reported to HHS) |
|---|---|
| Disclosed | Feb 10, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Compass Behavioral Health (Healthcare Provider, KS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 10, 2023 | 537 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.