St Vincent Medical Group
Disclosed Apr 10, 201511 years ago756 affectedConfirmed
St. Vincent Medical Group, Inc., the covered entity (CE), reported that on December 3, 2014, it learned that an employee’s user name and password had been compromised as a result of a phishing email attack. This breach affected approximately 756 individuals. The protected health information (PHI) involved in the breach included names, addresses, dates of birth, clinical information, and in some cases, and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE disabled and reset the password for the email account responsible for the breach, and required the employee to reset their password. It also deployed software to scan internet addresses in employees’ emails to determine if they are malicious, and required phishing training for all employees. OCR obtained documented assurances that the CE implemented the corrective action steps listed above.
What is known
| People affected | 756 (as reported to HHS) |
|---|---|
| Disclosed | Apr 10, 2015 |
| Happened | Dec 3, 2014 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2015 data breach report: St Vincent Medical Groupin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): St.Vincent Medical Group (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Apr 10, 2015 | 32 |
| HHS archivetotal | Apr 10, 2015 | 756 |
| Indiana AGresidents of IN | Jul 15, 2015 | 4 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: organization to hhs · backfill source
- 2026-09-25 · records: 32 to 756 · backfill source
- 2026-09-25 · summary: empty to St. Vincent Medical Group, Inc., the covered entity (CE), reported that on December 3, 2014, it learned that an employee’s user name and password had been compromised as a result of a phishing email attack. This breach affected approximatel · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.