Kenosha Community Health Center
Disclosed May 3, 20224 years ago2,688 affectedConfirmed
The covered entity (CE), Kenosha Community Health Center, reported that one of its employees was the victim of an email phishing attack that compromised the protected health information (PHI) of 2,688 individuals. The PHI involved names, dates of birth, Social Security numbers, diagnoses, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards. Employees were retrained on email security.
What is known
| People affected | 2,688 (as reported by the organization) |
|---|---|
| Disclosed | May 3, 2022 |
| Happened | Aug 24, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2022 data breach report: Kenosha Community Health Centerin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Kenosha Community Health Center (Healthcare Provider, WI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | May 3, 2022 | 1 |
| HHS archivetotal | May 3, 2022 | 2,688 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Kenosha Community Health Center, reported that one of its employees was the victim of an email phishing attack that compromised the protected health information (PHI) of 2,688 individuals. The PHI involved names, da · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.