25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

140,209 Patients Notified of Kalispell Regional Healthcare Phishing Attack

Kalispell Regional Healthcare in Montana is in the process of notifying approximately 140,000 patients that some of their protected health information (PHI) was potentially compromised in a security breach over the summer.

Kalispell Regional Healthcare operates Kalispell Regional Medical Center, a 138-bed hospital in Kalispell, MT. The breach has affected most of its patients.

The breach affected Kalispell Regional’s email system and was the result of multiple employees being fooled by a “highly sophisticated” phishing scam. Employees responding to the phishing email inadvertently disclosed their login credentials to the attacker who used the credentials to remotely access their email accounts. Kalispell Regional learned of the breach on August 28.

Upon discovery of the breach, all affected email accounts were disabled to prevent further unauthorized access, the security breach was reported to law enforcement, and an internal investigation was launched to determine the extent of the breach. The investigation revealed the email account was breached on May 24, 2019 and the compromised accounts contained messages and email attachments that included patients’ PHI.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The types of data exposed varied from patient to patient and may have included names, addresses, email addresses, telephone numbers, dates of service, treatment information, health insurance information, treating and referring physicians’ names, and medical bill account numbers. 250 or fewer patients also had their Social Security number exposed.

Unauthorized PHI access was possible, but no evidence has been uncovered to suggest any patient information has been misused; however, out of an abundance of caution, affected individuals have been offered complimentary membership to credit monitoring and identity theft protection services with Kroll for 12 months, regardless of the types of information that were exposed.

It took several weeks to discover which patients had been affected and the types of information that had been exposed, hence the delay in issuing breach notification letters. The breach investigation concluded last week.

Kalispell Regional had implemented a range of cybersecurity measures prior to the breach and uses a third-party firm to conduct annual threat assessments to proactively identify vulnerabilities and improve its security posture. Those measures were insufficient to block the phishing attack in this instance. Kalispell Regional will continue to review its security measures and enhancements will be made to better protect patient data against phishing attacks.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights on October 22, 2019 indicates up to 140,209 patients were affected by the security breach.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist