TRINITY HEALTH CORPORATION
ent_019ebb6181175f17daaf65de85efed6d
Disclosures
10
HHS OCR · State AG · 6 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
586,869
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TRINITY HEALTH CORPORATION
- Normalized
- trinity health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- TWSRHFGEDJDX0GKMGJ67
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- trinity-health.org
Disclosure history (10)newest first
- MIHHS OCRas victim2026-05-13
Trinity Health reported to HHS on 2026-05-13 a Unauthorized Access/Disclosure affecting 5905 individuals. Breached information located on Email.
- MIHHS OCRas victim2026-03-13
Trinity Health (MI), a Business Associate, reported to HHS OCR on 2026-03-13 an Unauthorized Access/Disclosure breach affecting 2,740 individuals. Breached information was located on Electronic Medical Records. A business associate was present.
- 🍁Vermont State AGas victim2026-03-13
Trinity Health notified Vermont AG of a potential unauthorized disclosure of patient health information via HIE partner Health Gorilla on Jan 13, 2026. Data may include clinical details, demographics, insurance info, and driver's license numbers. Trinity Health suspended the involved companies from the HIE and is offering 12 months of credit monitoring.
- 🦀Maryland State AGas victim2025-02-07
Trinity Village, a senior living community, notified the Maryland AG that staff used an unapproved, non-HIPAA-compliant mobile application to share non-critical PHI (lab/radiology results, condition changes) with one another. One Maryland resident was affected. No third-party access or financial data was compromised. Staff were instructed to stop using the app, communications were deleted, and staff were re-educated on HIPAA compliance.
- MIHHS OCRas victim2023-03-06
Trinity Health reported to HHS on 2023-03-06 a Hacking/IT Incident affecting 46,526 individuals. Breached information located on Email. An employee was targeted by a phishing scheme compromising PHI including names, addresses, DOB, financial info, and treatment data. The BA strengthened access controls and retrained staff.
- 🐻California State AGas victim2021-04-05
Trinity Health, a multi-institutional Catholic health care system, disclosed a security incident involving its third-party vendor, Accellion. On January 29, 2021, Accellion notified Trinity Health of a flaw in its File Transfer Appliance. An unknown user exploited this vulnerability to download files containing protected health information (PHI), including patient names, addresses, dates of birth, medical record numbers, and financial data. Trinity Health took the appliance offline, launched an investigation, and offered one year of complimentary credit monitoring and identity theft restoration services to affected patients.
- 🦞Maine State AGas victim2021-04-05
Trinity Health reported an external system breach (hacking) occurring on January 20, 2021, discovered on February 4, 2021. The incident compromised the personal information of 586,869 individuals, including names and Social Security Numbers. Trinity Health notified affected individuals in writing on April 5, 2021, and provided 12 months of credit monitoring services through Kroll. Three Maine residents were specifically identified as affected.
- 🦬Montana State AGas victim2020-10-23
Trinity Health reported a data breach to the Montana Attorney General. The breach was reported on 2020-10-23. The breach occurred from 4/18/2020 to 5/16/2020. 4 Montana residents were affected.
- 🐻California State AGas victim2020-10-23
Trinity Health notified California regulators of a ransomware attack on third-party vendor Blackbaud's network (April 18 - May 16, 2020). The incident impacted donor and patient database backups, exposing PII (names, addresses, emails) and PHI (patient status, insurance). Trinity Health offered 12 months of identity monitoring via Kroll.
- 🦞Maine State AGas victim2020-10-23
Trinity Health, a healthcare organization, reported a data breach affecting 6,288 individuals, including 6 Maine residents. The breach, which occurred between April 18, 2020, and May 16, 2020, was discovered on July 16, 2020. It was caused by a system breach at a third-party vendor. The compromised information included names combined with financial account numbers or credit/debit card numbers along with their security codes. Trinity Health began notifying affected Maine residents in writing on September 14, 2020, and offered 12 months of credit and identity theft monitoring services through Kroll.