Monarch
Disclosed Dec 16, 20223 years ago57,564 affectedConfirmed
The covered entity (CE), Monarch, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 56,155 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, drivers’ license numbers, medications, health insurance information, claims and financial information, and other treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE offered free credit monitoring to affected individuals and implemented additional administrative, technical, and security safeguards.
What is known
| People affected | 57,564 (as reported by the organization) |
|---|---|
| Disclosed | Dec 16, 2022 |
| Happened | Aug 20, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2023 data breach report: Monarchin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Monarch (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Dec 16, 2022 | 5 |
| HHS archivetotal | Dec 16, 2022 | 56,155 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Monarch, reported that it experienced a ransomware incident that affected the protected health information (PHI) of 56,155 individuals. The PHI involved included names, dates of birth, addresses, Social Security num · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.