Johns Hopkins Health System
Disclosed Jun 23, 20233 years ago363,885 affectedConfirmed
John Hopkins Health System Corporation, the covered entity (CE), reported that it experienced a malware attack that compromised the protected health information (PHI) of 2,584 individuals. The PHI involved included names, addresses, birthdates, and treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional technical safeguards.
What is known
| People affected | 363,885 (as reported by the organization) |
|---|---|
| Disclosed | Jun 23, 2023 |
| Happened | May 29, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2023 data breach report: Johns Hopkins Health Systemin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Johns Hopkins Health System (Business Associate, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 23, 2023 | 87 |
| HHS archivetotal | Jul 31, 2023 | 2,584 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to John Hopkins Health System Corporation, the covered entity (CE), reported that it experienced a malware attack that compromised the protected health information (PHI) of 2,584 individuals. The PHI involved included names, addresses, birthda · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.