The covered entity (CE), Meridian Health Services Corporation, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 111,372 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license information, Social Security numbers, diagnoses/conditions, lab results, medications prescribed, state identification numbers, and health insurance and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its PHI. In addition, the CE retrained its workforce members on the proper methods of identifying fraudulent email communications.
What is known
People affected
111,372 (as reported by the organization)
Disclosed
Apr 27, 2020
Discovered
Apr 3, 2020
Happened
Dec 9, 2019
Attack
Hacking
Data exposed
Names, Social Security numbers, Government IDs, Payment cards, Financial, Health
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: ["names","ssn","government-id","payment-card","financial"] to ["names","ssn","government-id","payment-card","financial","health"] · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Meridian Health Services Corporation, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 111,372 individuals. The PHI involved includ · backfill source
2026-09-25 · data_types: [] to ["names","ssn","government-id","payment-card","financial"] · backfill source
2026-09-25 · discovered: empty to 2020-04-03 · backfill source