Skip to content

Maryville Academy

Disclosed Nov 8, 201213 years ago3,897 affectedConfirmed

Official notice

Three secondary back-up portable hard drives, which were maintained by the covered entity (CE), Maryville Academy, were removed from a locked room used as a secure area to maintain a secondary back-up copy of some electronic records for the CE’s services programs. The drives contained the electronic protected health information (ePHI) of approximately 3,897 individuals, including patients’ names, dates of birth, telephone numbers, social security numbers, addresses, diagnosis/conditions, financial claims information, medications, lab results, and other treatment information. The CE provided breach notification to HHS, affected individuals, and the media, and posted notification of the breach on its website. The CE also offered one year of free credit monitoring services to affected individuals. Following the breach, the CE revised its HIPAA policies and procedures and encrypted its back-up portable hard drives and other portable electronic devices. It also updated its practices regarding the physical storage of its back-up portable hard drives to include the use of a third party, off-site vendor and contracted with a third party vendor for long term offsite archive storage, and tra

What is known

People affected3,897 (as reported to HHS)
DisclosedNov 8, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Maryville Academy (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 8, 20123,897

Other breaches at Maryville Academy

BreachAffected
Disclosed Sep 1, 2026Sep 13 weeks agoUnknown
Disclosed Aug 23, 2024Aug 23, 20242 years agoHacking513
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Maryville Academy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.