Skip to content

Episcopal Retirement Services

Disclosed Nov 18, 20214 years ago4,133 affectedConfirmed

Official notice

The covered entity (CE), Episcopal Retirement Services, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 4,133 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained.

What is known

People affected4,133 (as reported by the organization)
DisclosedNov 18, 2021
HappenedSep 24, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 18, 20214,133
Indiana AGresidents of INNov 19, 202160
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2021-11-19 to 2021-11-18 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Episcopal Retirement Services, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 4,133 individuals. The PHI involved included names, addresses, dates of · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Episcopal Retirement Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.