St. Charles Health System (SCHS), the covered entity (CE), reported that an employee accessed medical records without authorization. The breach affected approximately 2,459 individuals. The protected health information (PHI) involved included names, addresses, dates of birth, drivers’ license information, financial information, claims information, clinical information, and other treatment information. SCHS implemented physical, administrative, and security safeguards and re-trained its employees. The CE provided affected individuals with free credit monitoring and sanctioned workforce members involved. As a result of OCR’s investigation, SCHS confirmed that it initiated the process to upgrade its software that will allow SCHS to conduct medical record audits.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 2459 · backfill source
2026-09-25 · summary: empty to St. Charles Health System (SCHS), the covered entity (CE), reported that an employee accessed medical records without authorization. The breach affected approximately 2,459 individuals. The protected health information (PHI) involved includ · backfill source