Skip to content

Iowa Health System

Disclosed Apr 16, 20188 years ago1,421,107 affectedConfirmed

Official notice

Iowa Health System dba UnityPoint Health, the covered entity (CE), reported that multiple employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 1,421,107 individuals. The PHI involved included names, dates of birth, Social Security and drivers’ license numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. All staff were retrained.

What is known

People affected1,421,107 (as reported to HHS)
DisclosedApr 16, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Iowa Health System (Business Associate, IA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 16, 201816,429
HHS archivetotalJul 30, 20181,421,107

Other breaches at Iowa Health System

BreachAffected
Disclosed Sep 14, 2020Sep 14, 20206 years agoHacking27K
History of this record
  • 2026-09-25 · disclosed: 2018-07-30 to 2018-04-16 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Iowa Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.