Skip to content

Mitcon

Disclosed Dec 19, 20223 years ago4,002 affectedConfirmed

Official notice

The business associate (BA), MITCON, reported that it was the victim of a hacking attack affecting the protected health information (PHI) of 1,131 individuals. The PHI involved included names, addresses, Social Security and drivers’ license numbers, dates of birth, financial information, medications, and other treatment information. The BA notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional technical safeguards and provided complimentary credit monitoring services to affected individuals. OCR provided technical assistance regarding the HIPAA Security Rule.

What is known

People affected4,002 (as reported by the organization)
DisclosedDec 19, 2022
HappenedOct 18, 2022
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2023 data breach report: Mitconin.gov · Official notice
HHS OCR breach report (archive, resolved): MITCON (Business Associate, MI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 19, 20221,131
Indiana AGresidents of INFeb 16, 202313
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2023-02-16 to 2022-12-19 · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), MITCON, reported that it was the victim of a hacking attack affecting the protected health information (PHI) of 1,131 individuals. The PHI involved included names, addresses, Social Security and drivers’ license · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Mitcon

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.