Deaconess Health System Affected by Vendor Data Breach
Evansville, Indiana-based Deaconess Health System has announced a data breach involving information shared with a third-party vendor, the MRO Corp-owned company MediCopy. Deaconess Health System is one of the largest health systems in the Illinois-Indiana-Kentucky tri-state area, and operates 18 hospitals in southwestern Indiana, western Kentucky, and southeastern Illinois. The data breach affects certain patients of two of its hospitals: Deaconess Henderson Hospital in Henderson, KY, and Deaconess Union County Hospital in Morganfield, KY.
Deaconess Health System contracted with MediCopy to handle release of information (ROI) requests. Deaconess Health System’s substitute breach notice explains that MediCopy informed the health system about the security incident on February 2, 2026. The investigation determined that an unauthorized actor accessed MediCopy-controlled/managed cloud-based file-sharing software on January 13, 2026, and downloaded files related to ROI requests. The security incident was limited to the cloud-based platform. There was no unauthorized access to any Deaconess Health System’s IT systems or electronic health record system. A spokesperson for MRO said neither the MRO platform nor MediCopy systems were compromised in the incident.
Deaconess Health System conducted a comprehensive review of the affected data and determined that the information compromised in the incident included names, dates of birth, dates of service, medical record numbers, Social Security numbers, health insurance information, and medical records related to the treatment received at Deaconess Health System hospitals.
Notification letters are being mailed to the affected individuals by Deaconess Health System, which is offering complimentary credit monitoring and identity theft protection services. Deaconess Health System has confirmed that additional measures have been implemented to further strengthen the security of its file-sharing platform and the information maintained on that platform.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The number of Deaconess Health System patients affected by the data breach has yet to be publicly disclosed. Deaconess Health System said it has reported the breach to the appropriate agencies, but the breach is not yet shown on the HHS’ Office for Civil Rights breach portal. There has been a delay in adding data breaches to the OCR data breach portal. While there have been some additions of data breaches with reporting dates prior to February 26, 2026, the breach portal lists no new additions after that date (as of March 25, 2026).


