- State
- MS
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,489
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Alliance Health Partners, LLC (AHP), doing business as Tri-Lakes Medical Center, discovered on September 20, 2013, that its information system, which contains protected health information (PHI), had been infected by malware viruses since July 2012. The breach potentially affected the PHI of 3,241 individuals, including names, dates of birth, addresses, social security numbers, health claims and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. On January 27, 2014, Community Health Systems (CHS) acquired AHP and implemented its own HIPAA compliance program at the medical facility, including Privacy, Security and Breach Notification policies and anti-virus software and maintenance procedures. On May 18, 2015, the name of the medical center was changed to “Merit Health Batesville.” OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations. On May 1, 2017, AHP sold the medical facility and operations to a subsidiary of Curae Health (CHS), a non-profit healthcare system that specializes in assisting rural healthcare providers. Since that time, the facility operates as “Panola Medical Center” under Curae Health’s corporate structure, policies and procedures. OCR opened a separate review that includes the remaining CHS compliance issues.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.