Skip to content

Project Hospitality

Disclosed Sep 4, 20242 years ago89,476 affectedConfirmed

Official notice

The covered entity (CE), Project Hospitality, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 42,432 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses/conditions, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals and implemented additional administrative, technical, and security safeguards to better protect its PHI.

What is known

People affected89,476 (as reported by the organization)
DisclosedSep 4, 2024
HappenedJul 2, 2024
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 4, 202442,432
Vermont AGresidents of VTMay 7, 2025
Indiana AGresidents of INMay 7, 20254
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2025-05-07 to 2024-09-04 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Project Hospitality, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 42,432 individuals. The PHI involved included names, addresses, dates of birth, So · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 89476 · backfill source
  • 2026-09-25 · occurred: empty to 2024-07-02 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Vermont AG), confirmed by Vermont AG. Record counts are as reported. Not legal advice.

Everything about Project Hospitality

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.