TRINITY HEALTH CORPORATION
ent_019ebb6181175f17daaf65de85efed6d
Disclosures
25+
State AG · HHS OCR · 7 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
586,869
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TRINITY HEALTH CORPORATION
- Normalized
- trinity health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- TWSRHFGEDJDX0GKMGJ67
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- trinity-health.org
Disclosure history (newest 25)newest first
- Illinois State AGas victim2026-06-01
TRINITY HEALTH OF NEW ENGLAND filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1256). The register records the breach as discovered on April 30, 2026. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MICHIGANHHS OCRas victim2026-05-13
Trinity Health reported to HHS on 2026-05-13 a Unauthorized Access/Disclosure affecting 5905 individuals. Breached information located on Email.
- Massachusetts State AGas victim2026-03-13
Trinity Health notified Massachusetts residents on March 13, 2026, of a potential unauthorized disclosure of health information via a Health Information Exchange (HIE) partner. On January 13, 2026, Trinity Health was notified that an HIE member, Health Gorilla, may have improperly obtained patient data for treatment purposes without confirmed authorization. Affected data may include clinical care details, demographic information, insurance information, and potentially driver's license numbers. The involved companies have been suspended from the HIE. Trinity Health is offering 24 months of complimentary credit monitoring.
- MICHIGANHHS OCRas victim2026-03-13
Trinity Health (MI), a Business Associate, reported to HHS OCR on 2026-03-13 an Unauthorized Access/Disclosure breach affecting 2,740 individuals. Breached information was located on Electronic Medical Records. A business associate was present.
- Vermont State AGas victim2026-03-13
Trinity Health notified Vermont AG of a potential unauthorized disclosure of patient health information via HIE partner Health Gorilla on Jan 13, 2026. Data may include clinical details, demographics, insurance info, and driver's license numbers. Trinity Health suspended the involved companies from the HIE and is offering 12 months of credit monitoring.
- Illinois State AGas victim2026-03-01
TRINITY HEALTH filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1062). The register records the breach as discovered on January 13, 2026. Personal information types reported: drivers license, medical information. Additional entities named: LOYOLA UNIVERSITY MEDICAL CENTER, MERCYONE, TRINITY HEALTH MICHIGAN, SAINT FRANCIS HOSPITAL, MOUNT SINAI REHABILITATION HOSPITAL, JOHNSON MEMORIAL HOSPITAL, MERCY MEDICAL CENTER, SAINT MARY'S HOSPITAL. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2023-03-09
Trinity Health Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-09. 42,925 Massachusetts residents were affected. The report records the breach type as electronic.
- MICHIGANHHS OCRas victim2023-03-06
Trinity Health reported to HHS on 2023-03-06 a Hacking/IT Incident affecting 46,526 individuals. Breached information located on Email. An employee was targeted by a phishing scheme compromising PHI including names, addresses, DOB, financial info, and treatment data. The BA strengthened access controls and retrained staff.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-309). The register records the breach as discovered on July 22, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES/UNITYPOINT HEALTH - ROCK ISLAND filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-036). The register records the breach as discovered on March 9, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-462). The register records the breach as discovered on June 12, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-079). The register records the breach as discovered on January 1, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES/UNITYPOINT HEALTH - ROCK ISLAND filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-298). The register records the breach as discovered on April 19, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-434). The register records the breach as discovered on June 23, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH COPRORATION / MI filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-014). The register records the breach as discovered on December 16, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES/UNITYPOINT HEALTH - ROCK ISLAND filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-033). The register records the breach as discovered on April 18, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
TRINITY HEALTH ENTERPRISES filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-249). The register records the breach as discovered on March 20, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MICHIGANHHS OCRas victim2022-08-29
Trinity Health reported to HHS on 2022-08-29 a Unauthorized Access/Disclosure affecting 46,748 individuals. Breached information located on Network Server. The incident involved a hacking attack exposing PHI including names, addresses, DOBs, SSNs, and treatment data.
- Illinois State AGas victim2022-01-01
TRINITY HEALTH filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-169). The register records the breach as discovered on October 28, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2021-04-09
Trinity Health notified the NH AG of a data event affecting 1 NH resident. Unauthorized access occurred on Jan 20, 2021, via a flaw in Accellion's secure file transfer appliance. Data exposed: name, address, SSN. Trinity Health took the appliance offline and investigated. Notification sent April 5, 2021.
- California State AGas victim2021-04-05
Trinity Health notified patients of a security incident involving its third-party vendor, Accellion. An unknown user exploited a previously unknown vulnerability in the Accellion File Transfer Appliance to download files containing protected health information (PHI) on January 20, 2021. Trinity Health was notified on January 29, 2021, and immediately took the appliance offline. The breach affected patients across multiple states. Trinity Health is offering credit monitoring services.
- Maine State AGas victim2021-04-05
Trinity Health reported an external system breach (hacking) occurring on January 20, 2021, discovered on February 4, 2021. The incident compromised the personal information of 586,869 individuals, including names and Social Security Numbers. Trinity Health notified affected individuals in writing on April 5, 2021, and provided 12 months of credit monitoring services through Kroll. Three Maine residents were specifically identified as affected.
- MICHIGANHHS OCRas victim2021-04-05
Trinity Health reported to HHS on 2021-04-05 a Hacking/IT Incident affecting 586,869 individuals. Breached information located on Network Server. PHI included names, addresses, DOB, SSNs, claims, financial info, diagnoses, lab results, and medications.
- Massachusetts State AGas victim2021-04-05
Trinity Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-04-05. 152 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2020-11-02
Trinity Health notified the NH AG of a third-party ransomware attack on vendor Blackbaud (April-May 2020). Impacted data includes names, addresses, emails, financial account info, and PHI (patient status/insurance) for ~9 NH residents. Notification sent Sept 2020; 12 months identity monitoring offered.
Supply-chain cascadesreviewed and confirmed
- TRINITY HEALTH CORPORATION’s filing is one of at least 12 in the Accellion supply-chain incident (2021).
- TRINITY HEALTH CORPORATION’s filing is one of at least 175 in the BLACKBAUD, INC. supply-chain incident (2020).