- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,009
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized individual obtained the network credentials of a Brigham and Women’s Hospital (BWH) employee and used the credentials to access the employee’s work email account and potentially the employee’s personal Gmail account, which contained work-related emails. The protected health information (PHI) of 1,009 patients was potentially accessed, including names, birthdates, medical record numbers, providers’ name, dates of service, diagnoses/conditions, and treatment information. Following discovery of the breach, the covered entity (CE) sanctioned the employee who was using her personal email for work-related purposes and re-trained all employees. Additionally, the CE enhanced its technical safeguards regarding network credentials. The CE provided breach notification to HHS, affected individuals, and the media, and established a dedicated call center to answer questions. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.