Summit Medical Associates
Disclosed Aug 4, 20206 years ago7,264 affectedConfirmed
The covered entity (CE), Summit Medical Associates, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 7,264 individuals. The PHI involved included names, dates of birth, Social Security numbers, diagnoses, lab results, medications, and other treatment information. During the course of OCR’s investigation, the CE shuttered its medical practice and as a result, OCR closed the investigation.
What is known
| People affected | 7,264 (as reported by the organization) |
|---|---|
| Disclosed | Aug 4, 2020 |
| Happened | Jan 24, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2020 data breach report: Summit Medical Associatesin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Summit Medical Associates (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 4, 2020 | 7,264 |
| Indiana AGresidents of IN | Aug 7, 2020 | 7,018 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · disclosed: 2020-08-07 to 2020-08-04 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Summit Medical Associates, reported that it was the victim of a ransomware attack affecting the protected health information (PHI) of 7,264 individuals. The PHI involved included names, dates of birth, Social Securi · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.