Skip to content

Institute on Aging

Disclosed Jul 20, 20188 years ago3,907 affectedConfirmed

Official notice

On July 20, 2018, the covered entity (CE), Institute on Aging, in San Francisco, California, reported that phishing attacks compromised several workforce members' email accounts. The compromised email folders contained 3,907 patient’s protected health information (PHI), including demographic, clinical, and payment information. The CE provided breach notification to HHS, affected individuals, and the media and provided individuals with identity protection services. In response to the breach, the CE hired a security company to perform forensic investigation of the incident, added an advanced threat protection tool to prevent future occurrences of similar incidents, and retrained workforce members. The CE also provided OCR with additional documentation including its HIPAA Notice of Privacy Practices Policy, as relevant to this breach investigation. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected3,907 (as reported to HHS)
DisclosedJul 20, 2018
HappenedMay 28, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Institute on Agingoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): Institute on Aging (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAJul 20, 2018
HHS archivetotalJul 20, 20183,907
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 3907 · backfill source
  • 2026-09-25 · summary: empty to On July 20, 2018, the covered entity (CE), Institute on Aging, in San Francisco, California, reported that phishing attacks compromised several workforce members' email accounts. The compromised email folders contained 3,907 patient’s prote · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Institute on Aging

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.