- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,050
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee who is not involved in patient care followed a link in a phishing email to a website and provided credentials allowing access to the employee’s email account on May 9, 2018. On May 22, 2018, upon discovering that an unknown individual gained access to the account and created unauthorized rules, the covered entity (CE) immediately notified its IT department. The CE also retained a computer forensic investigation firm that discovered that the compromised account’s activity could not be audited. The CE treated the incident as a breach of the employee’s entire email account and found that the email account contained protected health information (PHI) on August 8, 2018. The PHI involved in the breach included the names, addresses, dates of birth, social security numbers, claims information, lab results, and other treatment information of approximately 2,050 individuals. The CE provided breach notification to HHS, affected individuals, and the media, as well as substitute notice. Following the breach, the CE reset the password on the compromised account, disabled the rules that were created, and confirmed that no other email accounts were compromised. Additionally, the CE created an alert for when a user creates automatic forwarding rules, enabled two-factor authentication for all employees, retrained employees on privacy and security requirements, and implemented a forced email password change policy. OCR provided the CE with technical assistance regarding its security management process.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.