Skip to content

Kaleida Health

Disclosed Jul 21, 20179 years ago2,789 affectedConfirmed

Official notice

The covered entity (CE), Kaleida Health, reported that numerous employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 744 individuals. The ePHI involved included names, medical record numbers, dates of birth, diagnoses, Social Security numbers, health insurance information, treatment information, and other clinical information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE revised its policies and procedures to better protect its sensitive data and retrained it workforce members. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected2,789 (as reported to HHS)
DisclosedJul 21, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Kaleida Health (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 21, 20172,789
HHS archivetotalAug 25, 2017744
History of this record
  • 2026-09-25 · records: 744 to 2789 · backfill source
  • 2026-09-25 · disclosed: 2017-08-25 to 2017-07-21 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Kaleida Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.