HopeWay Foundation
Disclosed May 20, 20251 year ago3,523 affectedConfirmed
The covered entity (CE), HopeWay Foundation, reported that multiple employees were the targets of an email phishing scheme that compromised the protected health information (PHI) of 3,523 individuals. The PHI contained demographic and clinical information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE provided security awareness training to its workforce and enhanced its access controls to better protect PHI. OCR provided technical assistance to the CE regarding the HIPAA Rules.
What is known
| People affected | 3,523 (as reported to HHS) |
|---|---|
| Disclosed | May 20, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): HopeWay Foundation (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 20, 2025 | 3,523 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.