OH Muhlenberg
Disclosed Nov 13, 201510 years ago84,700 affectedConfirmed
The FBI notified the covered entity (CE), OH Muhlenberg, LLC, on September 16, 2015, that its information system had been infected with malware known as “QuakBot.” Based on the CE’s internal investigation, it determined that the malware may have been present on its system as early as January 1, 2012 and may have affected its entire patient database of 84,506 patients. The types of protected health information (PHI) involved included names, dates of birth, addresses, phone numbers, driver’s licenses/state identification information, social security numbers, credit card/bank account numbers, health insurance information, and clinical information. In response to the breach, the CE decommissioned affected computers, replaced older computer hardware, implemented revised policies and procedures, improved antivirus protection and provided security awareness training to its workforce. The CE provided breach notification to HHS, to affected individuals, to the media and on its website. OCR obtained assurances that the CE implemented the corrective actions listed above
What is known
| People affected | 84,700 (as reported by the organization) |
|---|---|
| Disclosed | Nov 13, 2015 |
| Happened | Jan 1, 2012 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Government IDs, Payment cards, Financial, Passwords, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2015 data breach report: OH Muhlenbergin.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: OH Muhlenbergmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): OH Muhlenberg (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Nov 13, 2015 | 1,109 |
| Maine AGresidents of ME | Nov 13, 2015 | 9 |
| HHS archivetotal | Nov 13, 2015 | 84,681 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn","government-id","payment-card","financial","passwords"] to ["names","ssn","government-id","payment-card","financial","passwords","health"] · backfill source
- 2026-09-25 · summary: empty to The FBI notified the covered entity (CE), OH Muhlenberg, LLC, on September 16, 2015, that its information system had been infected with malware known as “QuakBot.” Based on the CE’s internal investigation, it determined that the malware may · backfill source
- 2026-09-25 · data_types: [] to ["names","ssn","government-id","payment-card","financial","passwords"] · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.