R1 RCM
Disclosed Mar 11, 20242 years ago16,121 affectedConfirmed
R1 RCM, the business associate (BA), reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 16,121 individuals. The PHI involved included names, addresses, dates of birth, social security numbers, diagnoses, and conditions. The BA notified HHS, the affected individuals, and the media. In its mitigation efforts, the BA implemented additional administrative and technical safeguards to better safeguard sensitive data.
What is known
| People affected | 16,121 (as reported by the organization) |
|---|---|
| Disclosed | Mar 11, 2024 |
| Happened | Jan 30, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2024 data breach report: R1 RCMin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): R1 RCM (Business Associate, IL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Mar 11, 2024 | 4 |
| HHS archivetotal | Mar 11, 2024 | 16,121 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to R1 RCM, the business associate (BA), reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 16,121 individuals. The PHI involved included names, addresses, dates of birth, social securi · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.