Perry County Memorial Hospital
Disclosed Oct 22, 20205 years ago4,538 affectedConfirmed
The covered entity (CE), Perry County Memorial Hospital, reported that several employees were the victims of an email phishing attack that affected the electronic protected health information (ePHI) of 4,538 individuals. The ePHI involved included names, addresses, telephone numbers, email addresses, clinical information, Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. The CE also offered one year of free credit monitoring services to affected individuals. In response to the breach, the CE strengthened its administrative and technical safeguards and retrained workforce members on phishing prevention to avoid similar incidents. OCR provided technical assistance to the CE regarding the HIPAA Rules.
What is known
| People affected | 4,538 (as reported to HHS) |
|---|---|
| Disclosed | Oct 22, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Perry County Memorial Hospital (Healthcare Provider, MO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 22, 2020 | 4,538 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.