Recovery Project
Disclosed Jun 28, 20215 years ago1,103 affectedConfirmed
The covered entity (CE), The Recovery Project, LLC, reported that an employee was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of 1,103 individuals. The ePHI involved included names, Social Security numbers, dates of birth and drivers’ licenses numbers. The CE notified HHS, affected individuals, the media, and provided credit monitoring services to affected individuals. In response to the breach, the CE strengthened its technical safeguards and retrained its staff on email security.
What is known
| People affected | 1,103 (as reported by the organization) |
|---|---|
| Disclosed | Jun 28, 2021 |
| Happened | Feb 23, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2021 data breach report: Recovery Projectin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Recovery Project (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 28, 2021 | 2 |
| HHS archivetotal | Jun 28, 2021 | 1,103 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), The Recovery Project, LLC, reported that an employee was the victim of an email phishing attack that affected the electronic protected health information (ePHI) of 1,103 individuals. The ePHI involved included names · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.