- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 8,300
- Business associate present
- No
- Type of breach
- Other
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Numerous employees of the CE responded to an email phishing attack which requested the employee’s email username and password to authenticate their accounts. As a result, a number of employee direct deposit paychecks were diverted without notification and any electronic protected health information (ePHI) stored on the affected email accounts was made accessible. The affected email accounts contained the combined ePHI of 8,311 individuals. The ePHI involved in the breach included patients’ demographic, clinical and health insurance information and in some cases, social security numbers. In response to the incident, the affected users changed their passwords and the CE adjusted web filters. The CE improved technical safeguards to prevent future phishing attacks of this nature and accelerated the time table for its existing phishing education campaign for all employees. The CE provided a year of free credit monitoring and identity theft protection services to affected individuals. OCR’s investigation confirmed that the appropriate notifications were made and that corrective actions steps were taken.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.