A hospice chain has had to report a HIPAA data breach. On Dec. 22, 2022, Legacy Operating Company, LLC d/b/a/ Legacy Hospice filed notice of a data breach with the Maine Attorney General after learning that an unauthorized party was able to access several employee email accounts containing confidential patient data, notes Richard Console Jr. with Console & Associates. The HHS Office for Civil Rights lists the incident as a "Hacking/IT incident" via email. The incident resulted in an unauthorized party gaining access to consumers’ names, Social Security numbers, taxpayer identification numbers, dates of birth, dates of death, driver’s license numbers, government identification numbers, financial account information, credit or debit card information, passport numbers, and protected health information, Console notes in online analysis. After confirming that consumer data was leaked, Legacy Hospice began sending out data breach notification letters to all individuals who were impacted. The chain operates in Alabama, Arkansas, Louisiana, Mississippi, Missouri, Oklahoma, and Tennessee, according to its website.