Deaconess Health System Data Breach Exposes SSNs and Sensitive Medical Records of Patients

Published
March 19, 2026
Updated
August 7, 2026
Deaconess Health System Data Breach Exposes SSNs and Sensitive Medical Records of Patients
Deaconess Health System

Deaconess Health System, a major nonprofit healthcare network headquartered in Evansville, Indiana, disclosed a data breach that originated through its Release of Information vendor, MediCopy. The breach has affected 8,941 total individuals across the nation, including 374 Texas residents.

Deaconess learned of the breach on Feb. 2, 2026, when MediCopy notified the company of a data security incident. The company reported the incident to the U.S. Department of Health and Human Services and posted a notice of the incident on its website with details for affected patients.

On Jan. 13, 2026, an unauthorized actor accessed MediCopy's cloud-based file sharing platform and downloaded files, according to the company's notification. The files contained Deaconess patient information related to Release of Information requests, which are formal processes through which patients or authorized parties obtain copies of medical records.

After learning of the incident, Deaconess began an investigation in coordination with MediCopy. The investigation confirmed that the unauthorized access and file download took place on Jan. 13, 2026. Deaconess then conducted a comprehensive review of the involved files to determine which individuals had their information included.

The breach was limited to certain patients of Deaconess Henderson Hospital in Henderson, Kentucky, and Deaconess Union County Hospital in Morganfield, Kentucky, along with their surrounding clinics. Only patients whose records were part of a Release of Information request were affected. The incident did not involve or impact any of Deaconess's own IT systems or its electronic medical record system, according to the notification.

The types of information exposed varied by individual but may have included names, Social Security numbers, dates of birth, medical record numbers, dates of service, health insurance identification numbers and medical records related to treatment received at Deaconess.

Deaconess Health System's response to the breach

In response to the breach, MediCopy implemented additional measures to strengthen the security of its file sharing platform and the Deaconess information it maintains, according to the notification. These changes are intended to help prevent a similar incident from occurring in the future.

Deaconess is mailing letters to patients whose information was involved in the breach. The company has arranged for affected patients to receive complimentary access to credit monitoring and identity protection services.

Deaconess has also set up a dedicated toll-free call center at 1-844-558-4567. The call center is available Monday through Friday between 9 a.m. and 5 p.m. Central Time.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
8941
Information Types Exposed
  • Name of individual
  • Social Security Number Information
  • Driver’s License number
  • Medical Information
  • Health Insurance Information
  • Date of Birth
  • Dates of service
  • Health insurance identification numbers
  • Medical record numbers
  • Names
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image