Fred Hutchinson Cancer Center, , the covered entity (CE), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 89,111 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license numbers, tax identification numbers, Social Security numbers, passport numbers, claims and financial information, health insurance information, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE provided complimentary credit monitoring and implemented additional administrative and technical safeguards. During the investigation, OCR provided the CE with technical assistance regarding the HIPAA Rules.
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 89111 · backfill source
2026-09-25 · summary: empty to Fred Hutchinson Cancer Center, , the covered entity (CE), reported that an employee was the subject of an email phishing scheme that compromised the protected health information (PHI) of 89,111 individuals. The PHI involved included names, · backfill source
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · disclosed: 2022-10-20 to 2022-05-25 · backfill source
2026-09-25 · discovered: empty to 2022-03-26 · backfill source