Back to the register

Atrium Health

ArchivedSubmitted 09/13/2024
State
NC
Covered entity type
Healthcare Provider
Individuals affected
32,120
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Atrium Health, the covered entity (CE), reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 32,120 patients of the CE. The PHI included patient names, dates of birth, addresses, driver’s license, Social Security Numbers, claims information, banking and financial information, medications, diagnoses and conditions, and other treatment information. The CE provided timely breach notification to the HHS Secretary, affected individuals, and media. The CE implemented additional administrative and technical safeguards.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Atrium Health (NC), 09/13/2024 | InfoSec Signals