Skip to content

People

Disclosed Apr 19, 20197 years ago970 affectedConfirmed

Official notice

The covered entity (CE), People, Inc., reported that several employees were victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 970 individuals. The ePHI involved included names, addresses, Social Security numbers, drivers’ license numbers, financial and health insurance information, medications prescribed, diagnoses, biometric data, radiographic information, and other treatment information. The CE notified HHS, affected individuals, the media, posted substitute notice on its website, and provided complimentary credit monitoring and identity protection services. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its ePHI. In addition, the CE retrained its workforce members on the proper methods of identifying and responding to fraudulent email communications.

What is known

People affected970 (as reported to HHS)
DisclosedApr 19, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): People (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 19, 2019970

Other breaches at People

BreachAffected
Disclosed Nov 6, 2020Nov 6, 20205 years agoHacking28K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about People

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.