Skip to content

Waystar Health

Disclosed Aug 25, 20206 years ago1,021 affectedConfirmed

Official notice

Waystar Health, a business associate (BA), reported that the electronic protected health information (ePHI) of 1,021 individuals was viewable via the Internet. The ePHI involved included names, dates of birth, addresses, Social Security numbers, and diagnoses/conditions. The BA notified HHS, affected individuals, the media, and posted substitute notice to its website. Upon discovering this incident, the BA implemented new administrative and technical safeguards to better protect sensitive data.

What is known

People affected1,021 (as reported to HHS)
DisclosedAug 25, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Waystar Health (Business Associate, KY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 25, 20201,021
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Waystar Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.