Geisinger Health
Disclosed May 20, 20206 years ago805 affectedConfirmed
The covered entity (CE), Geisinger Health, reported that a workforce member impermissibly accessed the electronic protected health information (ePHI) of 717 individuals. The ePHI involved included names, Social Security numbers, addresses, birthdates, medications prescribed, diagnoses, lab results, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE sanctioned the responsible employee and implemented additional administrative and technical safeguards to better protect its ePHI.
What is known
| People affected | 805 (as reported by the organization) |
|---|---|
| Disclosed | May 20, 2020 |
| Discovered | Mar 20, 2020 |
| Happened | Aug 1, 2017 |
| Attack | Insider |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: Geisinger Healthmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Geisinger Health (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Maine AGresidents of ME | May 20, 2020 | 1 |
| HHS archivetotal | Sep 23, 2020 | 717 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Geisinger Health, reported that a workforce member impermissibly accessed the electronic protected health information (ePHI) of 717 individuals. The ePHI involved included names, Social Security numbers, addresses, · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.