Drexel Medicine
Disclosed Aug 7, 20197 years ago4,340 affectedConfirmed
Drexel Medicine, the covered entity (CE), reported that it was the victim of an email phishing scheme involving the electronic protected health information (ePHI) of approximately 19,750 individuals. The ePHI involved included names, Social Security numbers, birthdates, diagnoses, and other treatment information. In its mitigation efforts, the CE implemented additional technical safeguards to better protect its sensitive data. Subsequently, Drexel Medicine has ceased operations.
What is known
| People affected | 4,340 (as reported to HHS) |
|---|---|
| Disclosed | Aug 7, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Drexel Medicine (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 7, 2019 | 4,340 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.