Hunt Memorial Hospital District
Disclosed Jun 29, 20188 years ago323,832 affectedConfirmed
Hunt Memorial Hospital District, the covered entity (CE), reported that an unauthorized user gained access to its electronic health records through a business associate’s (BA) email system via an email phishing scheme. The breach affected 1,887 individuals. The covered entity reported the breach to OCR, notified the affected individuals, and the media. The covered entity also improved its security posture and implemented additional training sessions for workforce members concerning password protection and HIPAA compliance. OCR obtained assurances that Hunt Memorial implemented the corrective actions noted above.
What is known
| People affected | 323,832 (as reported by the organization) |
|---|---|
| Disclosed | Jun 29, 2018 |
| Happened | May 18, 2018 |
| Attack | Insider |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2019 data breach report: Hunt Memorial Hospital Districtin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Hunt Memorial Hospital Districtmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Hunt Memorial Hospital District (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 29, 2018 | 1,887 |
| Indiana AGresidents of IN | Oct 7, 2019 | 213 |
| Maine AGresidents of ME | Oct 9, 2019 | 30 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · disclosed: 2019-10-07 to 2018-06-29 · backfill source
- 2026-09-25 · summary: empty to Hunt Memorial Hospital District, the covered entity (CE), reported that an unauthorized user gained access to its electronic health records through a business associate’s (BA) email system via an email phishing scheme. The breach affected 1 · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn"] · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.