Skip to content

Perry County Memorial Hospital

Disclosed Oct 22, 20205 years ago4,538 affectedConfirmed

Official notice

The covered entity (CE), Perry County Memorial Hospital, reported that several employees were the victims of an email phishing attack that affected the electronic protected health information (ePHI) of 4,538 individuals. The ePHI involved included names, addresses, telephone numbers, email addresses, clinical information, Social Security numbers, and claims and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. The CE also offered one year of free credit monitoring services to affected individuals. In response to the breach, the CE strengthened its administrative and technical safeguards and retrained workforce members on phishing prevention to avoid similar incidents. OCR provided technical assistance to the CE regarding the HIPAA Rules.

What is known

People affected4,538 (as reported to HHS)
DisclosedOct 22, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 22, 20204,538
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Perry County Memorial Hospital

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.