Hillcrest Nursing Center
Disclosed Nov 24, 20205 years ago1,030 affectedConfirmed
Hillcrest Nursing Center, the covered entity (CE), reported that a former employee impermissibly accessed its electronic medical records system containing the electronic protected health information (ePHI) of 1,030 individuals. The ePHI involved included names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, and treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its ePHI.
What is known
| People affected | 1,030 (as reported by the organization) |
|---|---|
| Disclosed | Nov 24, 2020 |
| Happened | Aug 4, 2020 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: Hillcrest Nursing Centerin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Hillcrest Nursing Center (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Nov 24, 2020 | 1 |
| HHS archivetotal | Nov 24, 2020 | 1,030 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to Hillcrest Nursing Center, the covered entity (CE), reported that a former employee impermissibly accessed its electronic medical records system containing the electronic protected health information (ePHI) of 1,030 individuals. The ePHI inv · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.