Skip to content

Hospital Authority of Valdosta and Lowndes County Georgia

Disclosed Jan 12, 20224 years ago41,692 affectedConfirmed

Official notice

The covered entity (CE), Hospital Authority of Valdosta and Lowndes County Georgia, reported that an employee impermissibly accessed and downloaded the protected health information (PHI) of 41,692 individuals to a USB drive. The PHI involved included names, dates of birth, medical records numbers, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, security, and physical safeguards. All staff were retrained on the HIPAA Rules.

What is known

People affected41,692 (as reported to HHS)
DisclosedJan 12, 2022
DiscoveredDec 3, 2021
HappenedNov 12, 2021
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 12, 202241,692
Oregon DOJresidents of ORJan 25, 202241,692
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 41692 · backfill source
  • 2026-09-25 · disclosed: 2022-01-25 to 2022-01-12 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Hospital Authority of Valdosta and Lowndes County Georgia, reported that an employee impermissibly accessed and downloaded the protected health information (PHI) of 41,692 individuals to a USB drive. The PHI involve · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Oregon DOJ), confirmed by Oregon DOJ. Record counts are as reported. Not legal advice.

Everything about Hospital Authority of Valdosta and Lowndes County Georgia

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.