Summit Surgical
Disclosed Dec 7, 20214 years ago4,910 affectedConfirmed
Summit Surgical, LLC, the covered entity (CE), reported that it was the target of a cybersecurity attack. The breach affected the protected health information (PHI) of 4,910 individuals. The breached PHI included names, addresses, dates of birth, social security numbers, claims information, and diagnoses/conditions. The CE notified HHS, affected individuals, and the media. The CE took several corrective actions in response to the breach, and OCR provided the CE with technical assistance regarding its health information privacy compliance obligations.
What is known
| People affected | 4,910 (as reported by the organization) |
|---|---|
| Disclosed | Dec 7, 2021 |
| Happened | Oct 8, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2022 data breach report: Summit Surgicalin.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Summit Surgical (Healthcare Provider, KS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 7, 2021 | 4,910 |
| Indiana AGresidents of IN | Mar 28, 2022 | 2 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · disclosed: 2022-03-28 to 2021-12-07 · backfill source
- 2026-09-25 · summary: empty to Summit Surgical, LLC, the covered entity (CE), reported that it was the target of a cybersecurity attack. The breach affected the protected health information (PHI) of 4,910 individuals. The breached PHI included names, addresses, dates of · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.