Cummins Behavioral Health Systems
Disclosed Apr 12, 20233 years ago154,285 affectedConfirmed
The covered entity (CE), Cummins Behavioral Health Systems, reported that it experienced a ransomware attack the affected the protected health information (PHI) of 154,285 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses/conditions, medications, and other treatment information. In response to the breach, the CE implemented additional administrative and technical safeguards. OCR provided the CE with technical assistance.
What is known
| People affected | 154,285 (as reported to HHS) |
|---|---|
| Disclosed | Apr 12, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Cummins Behavioral Health Systems (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 12, 2023 | 154,285 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.