Milestone Electric
Disclosed Oct 1, 20205 years ago4,973 affectedConfirmed
The covered entity (CE), Milestone Electric, reported that employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 4,973 individuals. The PHI involved included names, addresses, dates of birth, and Social Security numbers. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE implemented additional technical safeguards, updated its policies and procedures, and retrained its workforce members on email security.
What is known
| People affected | 4,973 (as reported to HHS) |
|---|---|
| Disclosed | Oct 1, 2020 |
| Happened | May 26, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Energy · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: Milestone Electricin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Milestone Electric (Health Plan, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Oct 1, 2020 | 1 |
| HHS archivetotal | Oct 8, 2020 | 4,973 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 3802 to 4973 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Milestone Electric, reported that employees were the victims of an email phishing attack that compromised the protected health information (PHI) of 4,973 individuals. The PHI involved included names, addresses, date · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.