Otis R. Bowen Center for Human Services
Disclosed Mar 2, 20206 years ago35,804 affectedConfirmed
The covered entity (CE), Otis R. Bowen Center for Human Services, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 35,804 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, drivers’ license information, diagnoses, and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE provided free credit monitoring services to those affected and implemented additional administrative, technical, and security safeguards to better protect its PHI. The CE also retrained its workforce members on the proper methods of identifying fraudulent email communications.
What is known
| People affected | 35,804 (as reported to HHS) |
|---|---|
| Disclosed | Mar 2, 2020 |
| Happened | Aug 6, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: Otis R. Bowen Center for Human Servicesin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Otis R. Bowen Center for Human Services (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Mar 2, 2020 | 4,572 |
| HHS archivetotal | Mar 20, 2020 | 35,804 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 4954 to 35804 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Otis R. Bowen Center for Human Services, reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 35,804 individuals. The PHI involved incl · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.