St. John's Riverside Hospital
Disclosed Nov 14, 202510 months ago2,238 affectedConfirmed
St. John’s Riverside Hospital, the covered entity (CE), reported that several employees were the targets of an email phishing scheme that compromised the protected health information (PHI) of 2,238 individuals. The PHI involved clinical and demographic information. The CE notified HHS and the affected individuals. In its mitigation efforts, the CE revised its policies and procedures regarding the HIPAA Privacy and Security Rules and trained or retrained its workforce. OCR provided technical assistance to the CE.
What is known
| People affected | 2,238 (as reported to HHS) |
|---|---|
| Disclosed | Nov 14, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): St. John's Riverside Hospital (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 14, 2025 | 2,238 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.