- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,600
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Carolina’s Medical Center, discovered that a physician had responded to a phishing email and provided her password to a third party, causing all of the physician’s emails to be forwarded to a third party. The forwarded emails included protected health information (PHI) regarding 5,600 individuals. The PHI in the emails included names, dates of birth, medications, treatment information, social security numbers (for 5 patients), dates of service, addresses, names of providers, admission/discharge dispositions and dates, and internal medical record and account numbers. Following the breach, CE improved administrative and technical safeguards by terminating auto-forwarding capabilities and implementing an alert for remote system accesses that originate from a foreign country. The CE also trained employees on identifying social engineering schemes. OCR obtained assurances that the corrective actions were taken.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.