HCF of Crestview
Disclosed Jan 8, 20251 year ago3,059 affectedConfirmed
The covered entity (CE), HCF of Crestview dba Village at the Greene, reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) 1,944 individuals. The PHI involved included names, addresses, Social Security numbers, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, and the media. In response to the breach the CE and BA provided complimentary credit monitoring services and implemented additional administrative and technical safeguards.
What is known
| People affected | 3,059 (as reported by the organization) |
|---|---|
| Disclosed | Jan 8, 2025 |
| Happened | Sep 17, 2024 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2025 data breach report: HCF of Crestviewin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): HCF of Crestview (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jan 8, 2025 | 2 |
| HHS archivetotal | Jan 9, 2025 | 1,944 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), HCF of Crestview dba Village at the Greene, reported that its business associate (BA) experienced a cyber-attack that compromised the protected health information (PHI) 1,944 individuals. The PHI involved included n · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.