Back to the register

Forrest General Hospital

ArchivedSubmitted 02/01/2018
State
MS
Covered entity type
Healthcare Provider
Individuals affected
1,670
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Horne CPAs & Business Advisors, a business associate (BA) of Forrest General Hospital (CE), discovered that a staff member’s email account was sending out suspicious emails after being compromised in a phishing attack. The BA investigated the incident, and determined that an email attachment to one of the emails in the compromised account contained the protected health information (PHI) of 1,671 of the CE’s patients. The types of breached PHI included names, Medicaid numbers, dates of service, dates of birth, patient account numbers, and Social Security numbers. The BA notified the CE, and worked with the CE to meet the requirements of the Breach Notification Rule. The BA provided breach notification to the affected individuals and the media. The CE provided notice to HHS and on its website. The BA sanctioned the employee involved and, in response to this incident and OCR’s investigation, the BA implemented several technical security improvements. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.