Skip to content

Maxim Healthcare Group

Disclosed Nov 4, 20214 years ago65,267 affectedConfirmed

Official notice

The covered entity (CE), Maxim Healthcare Group, reported that multiple employees were victims of an email phishing attack affecting the protected health information (PHI) of 65,267 individuals. The PHI involved includes names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services, changed passwords of affected accounts, implemented additional technical safeguards, and updated its policies and procedures.

What is known

People affected65,267 (as reported to HHS)
DisclosedNov 4, 2021
HappenedOct 1, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CANov 4, 2021
Indiana AGresidents of INNov 4, 2021124
HHS archivetotalNov 4, 202165,267
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 28833 to 65267 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Maxim Healthcare Group, reported that multiple employees were victims of an email phishing attack affecting the protected health information (PHI) of 65,267 individuals. The PHI involved includes names, addresses, d · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 28833 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Maxim Healthcare Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.