Skip to content

Graceworks Lutheran Services

Disclosed Mar 26, 20233 years ago6,737 affectedConfirmed

Official notice

Graceworks Lutheran Services, the covered entity (CE), reported that it experienced a ransomware attack that affected the protected health information (PHI) of 6,737 individuals. The PHI involved included names, addresses, dates of birth, social security numbers, claims information, diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE strengthened its administrative, technical, and security safeguards. OCR provided technical assistance regarding the HIPAA Rules.

What is known

People affected6,737 (as reported to HHS)
DisclosedMar 26, 2023
HappenedFeb 28, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INMar 26, 2023831
HHS archivetotalApr 19, 20236,737
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 4324 to 6737 · backfill source
  • 2026-09-25 · summary: empty to Graceworks Lutheran Services, the covered entity (CE), reported that it experienced a ransomware attack that affected the protected health information (PHI) of 6,737 individuals. The PHI involved included names, addresses, dates of birth, s · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Graceworks Lutheran Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.