Cornerstones of Care Data Breach
Cornerstones of Care Email Breach Affects 2,771 Patients
What happened in the Cornerstones of Care data breach?
The Cornerstones of Care data breach was reported on February 14, 2025 and affected 2,771 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Missouri. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Cornerstones of Care Breach Details
Cornerstones of Care Email Security Incident
Cornerstones of Care, a healthcare organization operating in Missouri, experienced a significant data breach involving unauthorized access to its email systems. The breach was reported to the Missouri Attorney General on February 14, 2025, affecting 2,771 individuals. The incident involved a hacking or IT-related compromise of email infrastructure, which typically serves as a central repository for patient communications, appointment scheduling information, and clinical correspondence containing protected health information (PHI).
Company Response
Upon discovery of the unauthorized access to their email systems, Cornerstones of Care initiated an investigation to determine the scope and nature of the compromise. The organization worked to identify which email accounts were affected, what information may have been accessed, and the timeframe during which the breach occurred. Following standard HIPAA breach notification requirements, the organization began the process of notifying affected individuals of the incident. The submission date of February 14, 2025, indicates this notification was made within the regulatory 60-day window required by HIPAA regulations for breach notification to affected parties.
Specific Details
Email system compromises represent a particularly significant threat vector in healthcare environments because email serves multiple critical functions: patient communication, clinical coordination between providers, appointment scheduling, billing inquiries, and transmission of test results and clinical notes. When email systems are compromised through hacking or IT incidents, the breadth of potentially exposed information can be substantial. The compromise likely involved unauthorized access to email accounts, which may have allowed threat actors to view, copy, or exfiltrate messages and attachments containing sensitive patient information. Email-based breaches typically occur through methods such as credential compromise (phishing, weak passwords, credential stuffing), exploitation of unpatched email server vulnerabilities, or compromise of email infrastructure through network penetration. The fact that this breach is classified as a hacking/IT incident rather than a loss or theft suggests active unauthorized access rather than physical loss of devices or documents.
Organizational Context
Cornerstones of Care operates as a healthcare provider organization in Missouri, serving patients across the state. The organization's name suggests a focus on foundational or comprehensive care services, though the specific service lines (behavioral health, primary care, specialty services, etc.) would determine the typical types of patient information maintained in their systems. Healthcare organizations of this size typically maintain extensive patient records including demographic information, medical histories, insurance details, and clinical documentation. The fact that 2,771 individuals were affected indicates a mid-sized healthcare operation or a breach affecting a significant portion of a smaller organization's patient population. The organization's email systems would have contained routine clinical and administrative communications typical of healthcare operations.
Patient Impact and Notifications
Approximately 2,771 patients and potentially other individuals (such as healthcare providers or business contacts) had their information potentially exposed through the email compromise. The individuals affected received notification of the breach in accordance with HIPAA requirements, which mandate notification without unreasonable delay and in no case later than 60 calendar days after discovery of a breach of unsecured PHI. The notification would have included information about the nature of the breach, the types of information involved, steps the organization is taking to investigate and remediate the incident, and recommended actions patients should take to protect themselves. Affected individuals were likely advised to monitor their accounts for suspicious activity and to consider placing fraud alerts or credit freezes if financial information was potentially exposed.
Industry Context and HIPAA Implications
Email-based breaches represent a significant and growing category of healthcare data breaches. According to HHS Office for Civil Rights data, email compromise incidents account for a substantial portion of reported healthcare breaches, often resulting from phishing attacks, credential compromise, or exploitation of email server vulnerabilities. HIPAA requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic PHI (ePHI), including access controls, encryption, and audit controls. Email systems should be protected through measures such as multi-factor authentication, email encryption, regular security updates, and employee security awareness training. The notification of this breach to the Missouri Attorney General and affected individuals reflects the organization's compliance with HIPAA Breach Notification Rule requirements. Healthcare organizations experiencing email compromises are typically required to conduct a thorough risk assessment to determine whether the breach poses a significant risk of harm to affected individuals, which determines the scope and method of notification required. The 2,771 individuals affected in this incident represents a moderate-scale breach in the healthcare context, where breaches affecting tens of thousands of individuals are not uncommon, but breaches of this size still warrant significant remediation and notification efforts.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Cornerstones of Care Breach
Monitor credit reports and financial accounts closely for signs of unauthorized activity; consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) or implementing a credit freeze to prevent unauthorized credit applications
Change passwords for email accounts and any healthcare provider portals or patient accounts, using strong, unique passwords and enabling multi-factor authentication where available
Review medical records and explanation of benefits (EOB) statements for unauthorized services or claims; contact your healthcare provider or insurance company immediately if you identify suspicious activity
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify the legitimacy of any requests for personal information by contacting the organization directly using a known phone number or website
Consider enrolling in identity theft protection or credit monitoring services if offered by the breached organization or through your insurance provider
Report any suspected identity theft or fraud to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a report with local law enforcement if necessary
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Missouri Breaches
Search all breaches reported in Missouri