Back to the register

Mississippi State Department of Health

ArchivedSubmitted 03/26/2018
State
MS
Covered entity type
Healthcare Provider
Individuals affected
30,799
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), the Mississippi State Department of Health, discovered that an employee accidentally sent an email on January 25, 2018, to contractors working on a joint project with an attached spreadsheet which the employee did not know contained the protected health information (PHI) of 30,799 individuals. The PHI in the spreadsheet included names, identification numbers, dates of birth, social security numbers, and sexually transmitted disease laboratory test results from 2017. The contractors confirmed that they did not retain or share the PHI. While the CE and the recipient of the email utilize transmission encryption protocols when sending emails, the CE was unable to confirm that the recipient email server accepted the email in encrypted format. There is no indication that the email had been intercepted. The CE provided timely breach notification to HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the employees at fault and provided onsite HIPAA training to employees. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.