South Suburban Surgical Suites
Disclosed Jun 30, 20233 years ago5,861 affectedConfirmed
The covered entity (CE), South Suburban Surgical Suites, reported that an employee was the victim of an email phishing incident that affected the protected health information (PHI) of 5,340 individuals. The PHI involved included names, addresses, dates of birth, Social Security and drivers’ license numbers, claims and financial information, diagnoses/conditions, medications, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional technical safeguards.
What is known
| People affected | 5,861 (as reported by the organization) |
|---|---|
| Disclosed | Jun 30, 2023 |
| Happened | Feb 20, 2023 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2023 data breach report: South Suburban Surgical Suitesin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): South Suburban Surgical Suites (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jun 30, 2023 | 5 |
| HHS archivetotal | Jun 30, 2023 | 5,340 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), South Suburban Surgical Suites, reported that an employee was the victim of an email phishing incident that affected the protected health information (PHI) of 5,340 individuals. The PHI involved included names, addr · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.