- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 21,311
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 2, 2018, the covered entity (CE), Reliable Respiratory, learned that a phishing email sent on June 28, 2018, comprised an employee’s email, potentially exposing the protected health information (PHI) of approximately 21,311 individuals. The types of PHI involved in the incident included demographic, clinical, and financial information. The CE provided breach notification to HHS, affected individuals, and the media, provided a call-center number and provided free credit monitoring. OCR obtained assurances that the CE implemented the corrective actions listed above. As a result of OCR’s investigation, the CE is working to implement additional safeguards such as email encryption solutions, more stringent inbound email filters targeted at catching and quarantining suspicious emails, and multifactor authentication.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.