Back to the register
Monroe Operations, LLC d/b/a Newport Academy and Center for Families
ArchivedSubmitted 08/17/2018
- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,165
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 20, 2018, the covered entity (CE), Monroe Operations, LLC d/b/a Newport Academy and Center for Families, discovered that an employee’s email account was phished on or about February 22, 2018, and the hacker set an automatic forwarding rule in the employee’s email inbox. Upon discovery, the CE immediately terminated the forwarding rule and changed the email account password. The CE identified one spreadsheet in the employee’s email account that contained the protected health information (PHI) of 1,165 individuals, including demographic and health insurance information, dates of admission, and medical record numbers. The CE provided breach notification to HHS and the affected individuals; media notification was not required. In response to the breach, the CE adopted, revised, and implemented Security Rule and Breach Notification policies and procedures, performed a risk analysis, implemented a safeguard requiring employees to update their passwords regularly, and assigned a staff member the responsibility for ensuring employee participation in HIPAA training. OCR provided technical assistance on automating review of the CE's computer system and the importance of regular HIPAA training. OCR obtained assurance that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.