Back to the register

Morehead Memorial Hospital

ArchivedSubmitted 09/15/2017
State
NC
Covered entity type
Healthcare Provider
Individuals affected
66,000
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

In late June 2017, employees at Morehead Memorial Hospital, the covered entity (CE), began reporting suspicious phishing emails to the information technology department. Through its contracted forensic investigator, Navigant Consulting, the CE found that two employee email accounts were compromised and protected health information (PHI) for about 66,000 individuals was exposed. The exposed PHI included treatment information, payment information, names, business reports, diagnostic information and for 1,200 individuals, their social security numbers as well. In response to the breach, the CE reset password for all employee accounts. The CE also added phishing information to employee training materials and created an internal website to improve reporting and notification of security incidents. The CE also verbally reminded employees directly involved with the compromised accounts about being vigilant and careful when email attachments. The CE provided breach notification to HHS, affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above. In response to the breach, Morehead initiated a master password reset for all employee accounts. Supplementary information on phishing was added to employee training materials and an internal website was created for better reporting and notification of security incidents. No employees were sanctioned; however, those directly involved with the compromised accounts were verbally reminded about being vigilant and careful in opening email attachments. Morehead provided timely and compliant breach notification to HHS, the affected individuals, and prominent media outlets in the affected jurisdictions. Substitute notice was posted on Morehead’s website in a timely and compliant manner as well.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.