Michigan Masonic Home
Disclosed Sep 16, 20242 years ago4,189 affectedConfirmed
The covered entity (CE), Michigan Masonic Home, reported that several employees were the targets of an email phishing scheme that compromised the protected health information (PHI) of 3,255 individuals. The PHI involved included names, addresses, dates of birth, Social Security and drivers’ license numbers, financial information, diagnoses/conditions, lab results, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect its PHI.
What is known
| People affected | 4,189 (as reported to HHS) |
|---|---|
| Disclosed | Sep 16, 2024 |
| Happened | Jul 30, 2024 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2025 data breach report: Michigan Masonic Homein.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Michigan Masonic Home (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 16, 2024 | 4,189 |
| HHS archivetotal | Nov 8, 2024 | 3,255 |
| Indiana AGresidents of IN | Dec 30, 2024 | 2 |
History of this record
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 3277 to 4189 · backfill source
- 2026-09-25 · disclosed: 2024-11-08 to 2024-09-16 · backfill source
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · disclosed: 2024-12-30 to 2024-11-08 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Michigan Masonic Home, reported that several employees were the targets of an email phishing scheme that compromised the protected health information (PHI) of 3,255 individuals. The PHI involved included names, addr · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.