Skip to content

Mercy Iowa City

Disclosed Mar 25, 201610 years ago15,625 affectedConfirmed

Official notice

Mercy Iowa City, the covered entity (CE), reported that it was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of approximately 15,625 individuals. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional technical safeguards and provided identity theft protection and credit monitoring services to affected individuals. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected15,625 (as reported to HHS)
DisclosedMar 25, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mercy Iowa City (Healthcare Provider, IA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 25, 201615,625

Other breaches at Mercy Iowa City

BreachAffected
Disclosed Nov 13, 2020Nov 13, 20205 years agoHacking93K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mercy Iowa City

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.