Goshen Health System
Disclosed Feb 14, 201214 years ago660 affectedConfirmed
Computer servers of Goshen Health System’s business associate (BA), Silver Tech, may have been injected with a virus on December 22, 2011. The BA operates a consumer website on behalf of the covered entity (CE) for employment and pre-registration for screenings and diagnostic testing. The BA’s servers contained the electronic protected health information (ePHI) of approximately 660 individuals, including patients’ names, social security numbers, addresses, insurance carriers, and testing information, and financial information. The CE provided breach notification to HHS, affected individuals, the media. It also notified the Indiana Attorney General’s office and the FBI and offered one year of free credit monitoring services to affected individuals. Following the breach, the CE terminated its relationship with the BA, engaged an outside forensic security firm to conduct an internal investigation, and updated its website. The CE revised its HIPAA policies and procedures and updated its practices to ensure the proper execution of Business Associate Agreements with all vendors and other parties who may have access to PHI. The CE trained its employees on its policies and procedures and d
What is known
| People affected | 660 (as reported to HHS) |
|---|---|
| Disclosed | Feb 14, 2012 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Goshen Health System (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 14, 2012 | 660 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.