Skip to content

R1 RCM

Disclosed Mar 11, 20242 years ago16,121 affectedConfirmed

Official notice

R1 RCM, the business associate (BA), reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 16,121 individuals. The PHI involved included names, addresses, dates of birth, social security numbers, diagnoses, and conditions. The BA notified HHS, the affected individuals, and the media. In its mitigation efforts, the BA implemented additional administrative and technical safeguards to better safeguard sensitive data.

What is known

People affected16,121 (as reported by the organization)
DisclosedMar 11, 2024
HappenedJan 30, 2023
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2024 data breach report: R1 RCMin.gov · Official notice
HHS OCR breach report (archive, resolved): R1 RCM (Business Associate, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INMar 11, 20244
HHS archivetotalMar 11, 202416,121
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to R1 RCM, the business associate (BA), reported that it experienced a cybersecurity incident that affected the protected health information (PHI) of 16,121 individuals. The PHI involved included names, addresses, dates of birth, social securi · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about R1 RCM

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.