Skip to content

Episcopal Health Services

Disclosed Nov 19, 20187 years ago218,055 affectedConfirmed

Official notice

The covered entity (CE), Episcopal Health Services, Inc., reported that numerous employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 218,055 individuals. The ePHI involved included names, dates of birth, addresses, Social Security numbers, drivers’ license numbers, financial information, diagnoses, mediations prescribed, and other treatment information. The CE notified HHS, affected individuals, the media, and provided free credit monitoring services to affected individuals. In its mitigation efforts, the CE implemented new administrative and technical safeguards to better protect its sensitive data. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected218,055 (as reported by the organization)
DisclosedNov 19, 2018
HappenedAug 28, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 19, 2018218,055
Indiana AGresidents of INApr 18, 20191

Other breaches at Episcopal Health Services

BreachAffected
Disclosed Jun 25, 2015Jun 25, 201511 years agoLost or stolen device509
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2019-04-18 to 2018-11-19 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Episcopal Health Services, Inc., reported that numerous employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 218,055 individuals. The ePHI involv · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Episcopal Health Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.