Mercy Health System
Disclosed Jul 2, 20197 years ago5,946 affectedConfirmed
Mercy Health System Corporation (MHSC), the covered entity (CE), reported that an employee of its business associate (BA) was the victim of an email phishing scheme that affected 5,946 individuals. The protected health information (PHI) involved included names, addresses, Social Security numbers, and treatment information. The CE, in conjunction with the BA, notified HHS, affected individuals, the media, and offered complimentary identity theft monitoring services. MHSC also provided substitute notice on its website.
What is known
| People affected | 5,946 (as reported to HHS) |
|---|---|
| Disclosed | Jul 2, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mercy Health System (Healthcare Provider, WI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 2, 2019 | 5,946 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.