- State
- MD
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,145
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Unauthorized users gained access to an employee’s email account after a phishing attack and automatically forwarded the employee’s emails to an external account. The breach included the protected health information (PHI) of 1,145 individuals and included names, addresses, dates of birth, social security numbers, and clinical information. Following the breach, the covered entity (CE), Associated Catholic Charities, added additional protection software to its email system and provided employees with additional security awareness training. Additionally, OCR reviewed the covered entity’s risk analysis to ensure compliance with the Security Rule. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.