Skip to content

LifeBridge Health

Disclosed May 15, 20188 years ago538,127 affectedConfirmed

Official notice

During an investigation of a malware attack on its computer server that hosts its electronic medical records, in March of 2018, the covered entity (CE) discovered that an unauthorized person accessed the server on September 27, 2016. The breach affected approximately 538,127 individuals and the types of protected health information (PHI) involved included demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE implemented its policies and procedures for contingency planning, data backup, disaster recovery, and emergency mode operations. OCR reviewed the CE's policies and procedures to ensure compliance with the Privacy and Security Rules. Following the breach, the CE implemented increased password controls. OCR obtained assurances that the CE implemented the corrective actions stated.

What is known

People affected538,127 (as reported to HHS)
DisclosedMay 15, 2018
HappenedSep 27, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: LifeBridge Healthoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): LifeBridge Health (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAMay 15, 2018
HHS archivetotalMay 15, 2018538,127

Other breaches at LifeBridge Health

BreachAffected
Disclosed Jan 8, 2025Jan 8, 20251 year agoHacking26K
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 538127 · backfill source
  • 2026-09-25 · summary: empty to During an investigation of a malware attack on its computer server that hosts its electronic medical records, in March of 2018, the covered entity (CE) discovered that an unauthorized person accessed the server on September 27, 2016. The br · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about LifeBridge Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.