Skip to content

Recovery Project

Disclosed Jun 28, 20215 years ago1,103 affectedConfirmed

Official notice

The covered entity (CE), The Recovery Project, LLC, reported that an employee was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of 1,103 individuals. The ePHI involved included names, Social Security numbers, dates of birth and drivers’ licenses numbers. The CE notified HHS, affected individuals, the media, and provided credit monitoring services to affected individuals. In response to the breach, the CE strengthened its technical safeguards and retrained its staff on email security.

What is known

People affected1,103 (as reported by the organization)
DisclosedJun 28, 2021
HappenedFeb 23, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Indiana Attorney General 2021 data breach report: Recovery Projectin.gov · Official notice
HHS OCR breach report (archive, resolved): Recovery Project (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INJun 28, 20212
HHS archivetotalJun 28, 20211,103
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), The Recovery Project, LLC, reported that an employee was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of 1,103 individuals. The ePHI involved included names · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Recovery Project

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.