Skip to content

Grand River Medical Group

Disclosed Feb 8, 20215 years ago37,858 affectedConfirmed

Official notice

Grand River Medical Group, the covered entity (CE), reported that an employee was the victim of an email phishing attack that compromised the protected health information (PHI) of 37,423 individuals. The PHI involved included names, addresses, Social Security numbers, dates of birth, claims information, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, the media, and provided complimentary credit monitoring services. In response to the breach, the CE strengthened its technical safeguards and retrained its staff on email security. OCR provided the CE with technical assistance regarding its HIPAA Security Rule obligations.

What is known

People affected37,858 (as reported by the organization)
DisclosedFeb 8, 2021
HappenedOct 19, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INFeb 8, 202120
HHS archivetotalFeb 12, 202137,423
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to Grand River Medical Group, the covered entity (CE), reported that an employee was the victim of an email phishing attack that compromised the protected health information (PHI) of 37,423 individuals. The PHI involved included names, address · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Grand River Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.