- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,310
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 8, 2013, the covered entity (CE), CaroMont Medical Group, performed an internal audit that found an unencrypted email was sent by an employee on August 5, 2013. The employee emailed a spreadsheet to her personal email containing the following protected health information (PHI) for 1,310 individuals: patients’ names, dates of birth, medical record numbers, insurance providers, insurance numbers, diagnoses, and two Medicaid/Medicare numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to this incident, the CE reviewed its policies, updated its secure email policy, and required employees to attest to reviewing the new policy. The CE trained staff on data privacy and information security, and it implemented security controls for the encryption of all external emails containing an attachment. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.