McAllen Hospitals
Disclosed Mar 20, 20233 years ago134,634 affectedConfirmed
The covered entity (CE), McAllen Hospitals dba South Texas Health System, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 134,634 individuals. The PHI involved included names, diagnoses, and financial and claims information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards and retrained staff on email security.
What is known
| People affected | 134,634 (as reported to HHS) |
|---|---|
| Disclosed | Mar 20, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): McAllen Hospitals (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 20, 2023 | 134,634 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.