Northern Iowa Therapy
Disclosed Oct 27, 20232 years ago5,529 affectedConfirmed
Northern Iowa Therapy, the business associate (BA), reported that it experienced a cyberattack that affected the protected health information (PHI) of 5,112 individuals. The breached PHI included names, addresses, dates of birth, social security numbers, phone numbers, email addresses, diagnoses and conditions, and health insurance and other treatment information. The BA notified HHS, the affected individuals, and the media. The BA took several corrective actions in response to the breach including implementing additional administrative and technical safeguards. OCR provided technical assistance regarding its health information privacy compliance obligations.
What is known
| People affected | 5,529 (as reported by the organization) |
|---|---|
| Disclosed | Oct 27, 2023 |
| Happened | Mar 10, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2023 data breach report: Northern Iowa Therapyin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Northern Iowa Therapy (Business Associate, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Oct 27, 2023 | 2 |
| HHS archivetotal | Oct 29, 2023 | 5,112 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to Northern Iowa Therapy, the business associate (BA), reported that it experienced a cyberattack that affected the protected health information (PHI) of 5,112 individuals. The breached PHI included names, addresses, dates of birth, social sec · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.