Back to the register

Northwest Surgical Specialists, P.C.

ArchivedSubmitted 10/05/2018
State
WA
Covered entity type
Healthcare Provider
Individuals affected
2,050
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

An employee who is not involved in patient care followed a link in a phishing email to a website and provided credentials allowing access to the employee’s email account on May 9, 2018. On May 22, 2018, upon discovering that an unknown individual gained access to the account and created unauthorized rules, the covered entity (CE) immediately notified its IT department. The CE also retained a computer forensic investigation firm that discovered that the compromised account’s activity could not be audited. The CE treated the incident as a breach of the employee’s entire email account and found that the email account contained protected health information (PHI) on August 8, 2018. The PHI involved in the breach included the names, addresses, dates of birth, social security numbers, claims information, lab results, and other treatment information of approximately 2,050 individuals. The CE provided breach notification to HHS, affected individuals, and the media, as well as substitute notice. Following the breach, the CE reset the password on the compromised account, disabled the rules that were created, and confirmed that no other email accounts were compromised. Additionally, the CE created an alert for when a user creates automatic forwarding rules, enabled two-factor authentication for all employees, retrained employees on privacy and security requirements, and implemented a forced email password change policy. OCR provided the CE with technical assistance regarding its security management process.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.