Esse Health
ent_35e9bee513d6fc53ccaf920c
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
521,167
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Esse Health
- Normalized
- esse health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🍁Vermont State AGas victim2025-09-10
Esse Health notified Vermont AG of a cyber event starting April 21, 2025, where a cybercriminal accessed the network and copied files containing patient PII and health information. The company engaged forensic specialists, notified law enforcement, and is offering IDX identity protection services. The EMR system was not accessed. Notification sent September 2, 2025.
- 🍁Vermont State AGas victim2025-06-30
Esse Health notified Vermont consumers of a cyber event discovered on April 21, 2025, where a cybercriminal gained unauthorized access to the network and copied files containing PHI, names, addresses, DOBs, and health insurance info. No SSNs were involved. Esse Health engaged forensic specialists, notified law enforcement, and offered IDX identity protection services.
- 🦞Maine State AGas victim2025-06-30
Esse Health, a healthcare organization, reported an external system breach (hacking) that was discovered on April 21, 2025. The breach affected 18 Maine residents. The company provided written notification to affected individuals and offered 12 months of identity protection services through IDX.
- 🏎️Indiana State AGas victim2025-06-25
Esse Health reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-21 and was reported on 2025-06-25. 454 Indiana residents were affected. 521,167 individuals affected in total.
- MOHHS OCRas victim2025-06-20
Esse Health, a healthcare provider in Missouri, reported to HHS OCR on 2025-06-20 a Hacking/IT Incident affecting 23,671 individuals. Breached information was located on a Network Server. No business associate was present. No further detail is available in the public disclosure.