Skip to content

Franciscan Medical Group

Disclosed Mar 28, 201412 years ago8,300 affectedConfirmed

Official notice

Numerous employees of the CE responded to an email phishing attack which requested the employee’s email username and password to authenticate their accounts. As a result, a number of employee direct deposit paychecks were diverted without notification and any electronic protected health information (ePHI) stored on the affected email accounts was made accessible. The affected email accounts contained the combined ePHI of 8,311 individuals. The ePHI involved in the breach included patients’ demographic, clinical and health insurance information and in some cases, social security numbers. In response to the incident, the affected users changed their passwords and the CE adjusted web filters. The CE improved technical safeguards to prevent future phishing attacks of this nature and accelerated the time table for its existing phishing education campaign for all employees. The CE provided a year of free credit monitoring and identity theft protection services to affected individuals. OCR’s investigation confirmed that the appropriate notifications were made and that corrective actions steps were taken.

What is known

People affected8,300 (as reported to HHS)
DisclosedMar 28, 2014
AttackNot stated
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 28, 20148,300

Other breaches at Franciscan Medical Group

BreachAffected
Disclosed Jan 13, 2011Jan 13, 201115 years agoLost or stolen device1,250
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Franciscan Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.