InfuSystem
Disclosed Jun 22, 20188 years ago3,882 affectedConfirmed
InfuSystem, Inc., the covered entity (CE), reported that it was the victim of an email phishing scheme. This breach affected approximately 3,882 individuals. The protected health information (PHI) involved included names, dates of birth, Social Security numbers, diagnoses, conditions, and medications prescribed. InfuSystem notified HHS, affected individuals, and the media. As a result of this breach, the CE implemented additional technical safeguards to better protect its PHI and retrained its staff. The employee responsible for the intrusion was sanctioned. OCR obtained assurances that the CE implemented the aforementioned corrective actions.
What is known
| People affected | 3,882 (as reported to HHS) |
|---|---|
| Disclosed | Jun 22, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): InfuSystem (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 22, 2018 | 3,882 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.