Summit Healthcare Association
Disclosed May 11, 20224 years ago1,410 affectedConfirmed
The covered entity (CE), Summit Healthcare Association, reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 1,410 individuals. The PHI involved included names, addresses, birthdates, Social Security numbers, and financial information. The CE notified HHS, affected individuals, the media, and posted substitute notice to its website. In its mitigation efforts, the BA provided free credit monitoring services and implemented new technical security measures, and retrained workforce members. OCR provided technical assistance regarding the HIPAA Rules.
What is known
| People affected | 1,410 (as reported to HHS) |
|---|---|
| Disclosed | May 11, 2022 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Summit Healthcare Association (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 11, 2022 | 1,410 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.