25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Email Breaches Reported by Mattapan Community Health Center and Prestera Center for Mental Health Services

Prestera Center for Mental Health Services, the largest behavioral health services provider in West Virginia, has discovered an unauthorized individual potentially accessed the protected health information of a small percentage of its current and former patients.

An unauthorized individual gained access to Prestera Center’s business email environment which contained protected health information such as patient names, dates of birth, medical record numbers, patient account numbers, diagnostic information, prescription information, treatment information, and healthcare provider information. The email system also contained a limited number of patient addresses, Social Security numbers, and Medicare/Medicaid numbers.

A third-party vendor was engaged to assist with the investigation and determine whether any PHI was viewed or obtained during the data security incident. Prestera Center said the investigation did not uncover any evidence of attempted or actual misuse of patient information, but since PHI may have been viewed or acquired, affected individuals have been offered complimentary identity theft restoration and credit monitoring services.

Prestera Center has taken steps to enhance security including implementing multi-factor authentication on all accounts, strengthening its cybersecurity infrastructure, replacing and strengthening the firewall, revising policies and procedures, and implementing an intensive training program for employees.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The HHS’ Office for Civil Rights breach portal indicates 3,708 individuals were affected by the breach.

Mattapan Community Health Center Email Breach

Mattapan Community Health Center (MCHC) in Massachusetts is notifying certain patients that some of their protected health information has potentially been viewed by an unauthorized individual who gained access to an employee’s email account.

Unusual email activity was detected on October 16, 2020 within an employee’s email account. Assisted by a third-party security firm, MCHC determined that the email account was accessed between July 28, 2020 and October 15, 2020. A review of the account revealed it contained sensitive data that may have been viewed or acquired.

The information in the account varied from individual to individual and may have included patient names, Social Security numbers, medical diagnoses, treatment information, provider information, health insurance information and/or medical record numbers.

MCHC said no evidence was found to indicate any actual or attempted misuse of patient data. MCHC has since implemented additional security measures to prevent further breaches.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Prevent HIPAA Email Violations

Avoid the common misunderstandings and implementation errors relating to HIPAA email.

Learn more