Skip to content

Otis R. Bowen Center for Human Services

Disclosed Mar 2, 20206 years ago35,804 affectedConfirmed

Official notice

The covered entity (CE), Otis R. Bowen Center for Human Services, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 35,804 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, drivers’ license information, diagnoses, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE provided free credit monitoring services to those affected and implemented additional administrative, technical, and security safeguards to better protect its PHI. The CE also retrained its workforce members on the proper methods of identifying fraudulent email communications.

What is known

People affected35,804 (as reported to HHS)
DisclosedMar 2, 2020
HappenedAug 6, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INMar 2, 20204,572
HHS archivetotalMar 20, 202035,804
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 4954 to 35804 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Otis R. Bowen Center for Human Services, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 35,804 individuals. The PHI involved incl · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Otis R. Bowen Center for Human Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.