On June 21, 2018, the covered entity (CE), Legacy Health, learned that an unauthorized third party may have gained access to some employees’ email accounts in May 2018, affecting approximately 38,000 individuals. The types of protected health information (PHI) involved in the breach included patients’ names, dates of birth, insurance information, billing information, driver's license numbers, Social Security numbers and medical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE began an investigation and engaged a law firm and other companies to assist. As a result of OCR’s investigation, the CE implemented enhanced email security protections, implemented multi-factor authentication for all users on all of its systems, and enhanced malware defenses on its firewall.
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 38000 · backfill source
2026-09-25 · disclosed: 2018-08-21 to 2018-08-20 · backfill source
2026-09-25 · summary: empty to On June 21, 2018, the covered entity (CE), Legacy Health, learned that an unauthorized third party may have gained access to some employees’ email accounts in May 2018, affecting approximately 38,000 individuals. The types of protected heal · backfill source