Knoxville Heart Group
Disclosed Apr 27, 20188 years ago15,995 affectedConfirmed
On February 26, 2018, the covered entity (“CE”), Knoxville Heart Group, Inc., discovered that an unauthorized third party gained access to its email system through a phishing email. The email system contained the protected health information (PHI) of 15,008 individuals, primarily on “rounding lists,” which contained demographic, clinical and healthcare claims information, as well as the Social Security numbers, driver’s licenses, and financial account numbers for 130 individuals. Prior to OCR’s investigation, the CE immediately terminated the unauthorized access, reset the email account password, blocked all internal emails coming from the compromised email account, retrained all of its employees, provided free credit monitoring services and identity theft insurance to individuals whose financial information was compromised and created a secure email messaging platform for its practitioners to use on mobile devices. After the commencement of OCR’s investigation, the CE conducted a risk analysis and revised its Security Rule policies and procedures to prevent reoccurrence. OCR provided the CE with technical assistance of risk analysis and management plans as well as phishing prevent
What is known
| People affected | 15,995 (as reported to HHS) |
|---|---|
| Disclosed | Apr 27, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Knoxville Heart Group (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 27, 2018 | 15,995 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.