Back to the register
South Carolina Department of Health and Human Services
ArchivedSubmitted 04/24/2012
- State
- SC
- Covered entity type
- Health Plan
- Individuals affected
- 228,435
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), South Carolina Department of Health and Human Services, discovered that an employee sent Medicaid reports to her personal email from January 31, 2012, through April 4, 2012. The breach affected 228,435 individuals and the types of protected health information (PHI) involved in the breach included names, addresses, phone numbers, social security numbers and for 22,648 individuals, their Medicaid identification numbers. The CE provided timely breach notification to HHS, affected individuals, and the media. CE also posted notification about the breach on its website. In response to the breach, CE suspended access to most of its ad hoc electronic reporting, initiated a comprehensive review of its privacy and security safeguards, contacted local and federal law enforcement, and sanctioned the responsible employee. The CE also revised its security policies to restrict employee access to PHI to only that necessary for the individual’s job function and implemented an automated monitoring system to track user activity in its computer system. CE also implemented annual privacy and security training. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.