Waystar Health
Disclosed Aug 25, 20206 years ago1,021 affectedConfirmed
Waystar Health, a business associate (BA), reported that the electronic protected health information (ePHI) of 1,021 individuals was viewable via the Internet. The ePHI involved included names, dates of birth, addresses, Social Security numbers, and diagnoses/conditions. The BA notified HHS, affected individuals, the media, and posted substitute notice to its website. Upon discovering this incident, the BA implemented new administrative and technical safeguards to better protect sensitive data.
What is known
| People affected | 1,021 (as reported to HHS) |
|---|---|
| Disclosed | Aug 25, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Waystar Health (Business Associate, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 25, 2020 | 1,021 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.