Deaconess Health System, a nonprofit healthcare provider, experienced a data breach in January 2026 when an unauthorized actor accessed cloud-based file-sharing software belonging to its vendor, MediCopy (also known as MRO Corp.). This incident exposed sensitive patient data from hospitals in Western Kentucky, including Deaconess Henderson Hospital and Deaconess Union County Hospital. It did not affect Deaconess's internal systems or electronic medical records. A separate ransomware attack by the worldleaks group targeted Deaconess Health System directly on April 8, 2026; however, details on affected individuals or data types from this incident are not provided.
The exposed data types from the vendor breach included names, Social Security numbers, dates of birth, medical record numbers, dates of medical service, health insurance identification numbers, and medical/treatment records. The exact number of individuals affected by either incident has not been publicly disclosed. While the vendor breach primarily impacted patients in Kentucky, Deaconess Health System operates in Indiana, Illinois, and Kentucky.
Details about the full scope of both incidents, including the number of affected individuals and specific notification dates, may emerge over time.