PIH HEALTH, INC.
ent_019e10cb61ada244f70fe82a095f384d
Disclosures
14
State AG · HHS OCR enforcement · HHS OCR · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,947,264
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PIH HEALTH, INC.
- Normalized
- pih health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IFY1T501PZ2S75
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- Vermont State AGas victim2026-04-30
PIH Health reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-04-30. The reporting organization type is Health Care. 138 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Oregon State AGas victim2026-03-18
PIH Health, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2026-03-18. The breach occurred during 12/1/2024. The breach was discovered on 12/16/2025. 2,351 individuals were affected. Notice was sent on 2/27/2026.
- Washington State AGas victim2026-03-04
PIH Health, Inc. notified Washington AG of a data security event discovered on Dec 1, 2024, affecting 3,639 residents. Unauthorized access led to exposure of names, SSNs, driver's licenses, DOB, and medical/insurance info. Notifications sent Feb 27, 2026, offering 12 months of Experian identity protection.
- Texas State AGas victim2026-03-03
PIH Health, Inc. based in Whittier, California, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-12-16 and reported on 2026-03-03. 8,434 Texas residents were affected. 1,369,533 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
- Illinois State AGas victim2026-03-01
PIH HEALTH, INC filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1078). The register records the breach as discovered on December 1, 2024. Personal information types reported: drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2026-02-27
PIH Health, Inc. notified the California Attorney General of a data security incident where an unauthorized actor accessed personal information. The breach occurred between November 14 and December 2, 2024, and was discovered on December 1, 2024. The incident affected 174 individuals, including Rhode Island residents. Affected data included names and other personal identifiers. PIH Health secured the network, conducted a forensic review, and is offering complimentary identity protection services.
- FEDERALHHS OCR enforcementas victim2025-04-23
HHS OCR settled with PIH Health, Inc. for $600,000 regarding a phishing attack that compromised 45 employee email accounts and exposed the ePHI of 189,763 individuals. The breach occurred between June 11 and June 21, 2019. The settlement includes a Corrective Action Plan addressing risk analysis, risk management, policies, and training.
- CALIFORNIAHHS OCRas victim2025-01-31
PIH Health, Inc. reported to HHS on 2025-01-31 a Hacking/IT Incident affecting 2,947,264 individuals. Breached information located on Network Server.
- Massachusetts State AGas victim2020-01-10
PIH Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-01-10. 12 Massachusetts residents were affected. The report records the breach type as electronic.
- CALIFORNIAHHS OCRas victim2020-01-10
PIH Health, Inc. reported to HHS OCR on 2020-01-10 a Hacking/IT Incident affecting 199,548 individuals. The breach involved a phishing attack in June 2019 that compromised employee email accounts, exposing unsecured ePHI including names, SSNs, and medical data. Location of breached info: Email.
- New Hampshire State AGas victim2020-01-10
PIH Health notified the NH AG of a phishing incident affecting 3 NH residents. Unauthorized access to employee email accounts occurred June 11-19, 2019. Exposed data included names, driver's licenses, medical info, and credentials. Notifications mailed Jan 9-10, 2020.
- California State AGas victim2020-01-10
PIH Health, a California healthcare provider, experienced a targeted phishing campaign resulting in unauthorized access to employee email accounts between June 11 and June 19, 2019. The incident was discovered on June 18, 2019. Approximately 159,879 California residents were affected, with exposure of names, SSNs, driver's license numbers, medical information, health insurance info, and online credentials. PIH Health engaged cybersecurity experts, reset passwords, implemented additional security measures, and offered credit monitoring.
- Indiana State AGas victim2020-01-10
PIH Health reported a data breach to the Indiana Attorney General. The breach occurred on 2019-06-11 and was reported on 2020-01-10. 24 Indiana residents were affected. 199,548 individuals affected in total.
- Illinois State AGas victim2020-01-01
PIH HEALTH filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-008). The register records the breach as discovered on June 18, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.