Summa Health, the covered entity (CE), reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 8,488 individuals. The PHI involved included names, dates of birth, Social Security numbers, health insurance information, email addresses, diagnoses/conditions, medications prescribed, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE implemented additional administrative and technical safeguards and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 7989 · backfill source
2026-09-25 · summary: empty to Summa Health, the covered entity (CE), reported that several employees were the victims of an email phishing scheme that affected the protected health information (PHI) of 8,488 individuals. The PHI involved included names, dates of birth, · backfill source
2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DecDataBreach.pdf · backfill source