Skip to content

Geisinger Health

Disclosed May 20, 20206 years ago805 affectedConfirmed

Official notice

The covered entity (CE), Geisinger Health, reported that a workforce member impermissibly accessed the electronic protected health information (ePHI) of 717 individuals. The ePHI involved included names, Social Security numbers, addresses, birthdates, medications prescribed, diagnoses, lab results, and other treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE sanctioned the responsible employee and implemented additional administrative and technical safeguards to better protect its ePHI.

What is known

People affected805 (as reported by the organization)
DisclosedMay 20, 2020
DiscoveredMar 20, 2020
HappenedAug 1, 2017
AttackInsider
Data exposedNames, Social Security numbers, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Maine Attorney General breach notice archive: Geisinger Healthmaine.gov · Official notice
HHS OCR breach report (archive, resolved): Geisinger Health (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Maine AGresidents of MEMay 20, 20201
HHS archivetotalSep 23, 2020717
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Geisinger Health, reported that a workforce member impermissibly accessed the electronic protected health information (ePHI) of 717 individuals. The ePHI involved included names, Social Security numbers, addresses, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.

Everything about Geisinger Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.