Skip to content

Tri Lakes Medical Center

Disclosed Jan 10, 201412 years ago1,489 affectedConfirmed

Official notice

The covered entity (CE), Alliance Health Partners, LLC (AHP), doing business as Tri-Lakes Medical Center, discovered on September 20, 2013, that its information system, which contains protected health information (PHI), had been infected by malware viruses since July 2012. The breach potentially affected the PHI of 3,241 individuals, including names, dates of birth, addresses, social security numbers, health claims and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. On January 27, 2014, Community Health Systems (CHS) acquired AHP and implemented its own HIPAA compliance program at the medical facility, including Privacy, Security and Breach Notification policies and anti-virus software and maintenance procedures. On May 18, 2015, the name of the medical center was changed to “Merit Health Batesville.” OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations. On May 1, 2017, AHP sold the medical facility and operations to a subsidiary of Curae Health (CHS), a non-profit healthcare system that specializes in assisting rural healthcare providers. Since that time

What is known

People affected1,489 (as reported to HHS)
DisclosedJan 10, 2014
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 10, 20141,489
HHS archivetotalJan 15, 20141,489
History of this record
  • 2026-09-25 · disclosed: 2014-01-15 to 2014-01-10 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Tri Lakes Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.