Hardin County Emergency Medical Services
Disclosed Nov 27, 20241 year ago1,046 affectedConfirmed
The covered entity (CE), Hardin County Emergency Medical Services, reported that an employee was the target of an email phishing scheme that affected the protected health information (PHI) of 1,046 individuals. The PHI involved demographic, clinical, and financial information. The CE notified HHS, affected individuals, and the media. In response to the breach the CE implemented additional technical safeguards and retrained the involved employee. OCR provided technical assistance regarding the HIPAA Security Rule and the Breach Notification Rule.
What is known
| People affected | 1,046 (as reported to HHS) |
|---|---|
| Disclosed | Nov 27, 2024 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Hardin County Emergency Medical Services (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 27, 2024 | 1,046 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.