- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 66,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
In late June 2017, employees at Morehead Memorial Hospital, the covered entity (CE), began reporting suspicious phishing emails to the information technology department. Through its contracted forensic investigator, Navigant Consulting, the CE found that two employee email accounts were compromised and protected health information (PHI) for about 66,000 individuals was exposed. The exposed PHI included treatment information, payment information, names, business reports, diagnostic information and for 1,200 individuals, their social security numbers as well. In response to the breach, the CE reset password for all employee accounts. The CE also added phishing information to employee training materials and created an internal website to improve reporting and notification of security incidents. The CE also verbally reminded employees directly involved with the compromised accounts about being vigilant and careful when email attachments. The CE provided breach notification to HHS, affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above.
In response to the breach, Morehead initiated a master password reset for all employee accounts. Supplementary information on phishing was added to employee training materials and an internal website was created for better reporting and notification of security incidents. No employees were sanctioned; however, those directly involved with the compromised accounts were verbally reminded about being vigilant and careful in opening email attachments. Morehead provided timely and compliant breach notification to HHS, the affected individuals, and prominent media outlets in the affected jurisdictions. Substitute notice was posted on Morehead’s website in a timely and compliant manner as well.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.