Skip to content

University Gastroenterology

Disclosed Aug 16, 201610 years ago15,478 affectedConfirmed

Official notice

An unauthorized person gained access to the covered entity’s (CE) electronic file storage system. The breach affected 15,478 individuals’ protected health information (PHI) and included patients’ names, addresses, dates of birth, social security numbers, and medical billing information. Following the breach, the CE completely dismantled the accessed system. OCR reviewed the CE’s policies and procedures for safeguarding PHI, which conform to the HIPAA Privacy and Security Rules. The CE provided OCR with assurances that it provided breach notification to affected individuals and the media.

What is known

People affected15,478 (as reported to HHS)
DisclosedAug 16, 2016
HappenedJan 15, 2016
AttackHacking
Data exposedNames, Social Security numbers, Health, Addresses
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INAug 16, 20161
Maine AGresidents of MESep 8, 201617
HHS archivetotalSep 8, 201615,478
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 15478 · backfill source
  • 2026-09-25 · summary: empty to An unauthorized person gained access to the covered entity’s (CE) electronic file storage system. The breach affected 15,478 individuals’ protected health information (PHI) and included patients’ names, addresses, dates of birth, social sec · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn","health","addresses"] · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about University Gastroenterology

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.