Skip to content

Endo Group

Disclosed Jan 27, 20251 year ago4,498 affectedConfirmed

Official notice

The covered entity (CE), Endo Group, LLC reported that multiple employees were the targets of an email phishing scheme that affected the protected health information (PHI) of 4,498 individuals. The PHI involved included names, Social Security numbers, addresses, drivers’ license numbers, dates of birth, financial and claims information, diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals and implemented additional administrative, technical, and security safeguards. Staff were retrained.

What is known

People affected4,498 (as reported to HHS)
DisclosedJan 27, 2025
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Endo Group (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJan 27, 20254,498
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Endo Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.