Skip to content

WyndRidge Health and Rehabilitation Center

Disclosed Nov 26, 20214 years ago1,958 affectedConfirmed

Official notice

The covered entity (CE), Wyndridge Health and Rehabilitation Center, reported that it was the victim of a ransomware attack that compromised the electronic protected health information (ePHI) of 1,958 individuals. The ePHI involved included names, addresses, photographs, dates of birth, Social Security numbers, medical record numbers, and clinical and health insurance information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE strengthened its technical safeguards, revised its security policies and procedures, and retrained its workforce members on HIPAA cybersecurity.

What is known

People affected1,958 (as reported by the organization)
DisclosedNov 26, 2021
HappenedSep 29, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 26, 20211,958
Indiana AGresidents of INJan 13, 20223
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · disclosed: 2022-01-13 to 2021-11-26 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Wyndridge Health and Rehabilitation Center, reported that it was the victim of a ransomware attack that compromised the electronic protected health information (ePHI) of 1,958 individuals. The ePHI involved included · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about WyndRidge Health and Rehabilitation Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.