25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Email Incidents Announced by SAG-AFTRA Health Plan & East Paris Internal Medicine Associates

A phishing attack on SAG-AFTRA Health Plan has exposed plan member data East Paris Internal Medicine Associates has discovered a former employee emailed patient data to a personal email account.

Phishing Attack Exposed SAG-AFTRA Health Plan Members’ PHI

SAG-AFTRA Health Plan, a provider of health benefits to media professionals, has discovered unauthorized access to an employee’s email account. The account breach was detected on September 18, 2024, and the account was immediately secured to prevent further unauthorized access. Third-party cybersecurity consultants were engaged to investigate the breach and determined there had been unauthorized access to the account from September 17 to September 18 due to a response to a phishing email.

The account was reviewed, and on October 3, 2024, it was confirmed that the protected health information of certain health plan members had been exposed. The review of the account is ongoing, but it has been confirmed that members’ names and Social Security numbers were involved, and for some of those individuals, claims information and health plan identification numbers. SAG-AFTRA Health Plan is evaluating and enhancing its security controls and will notify the affected individuals when the file review is concluded. Individuals who had their Social Security numbers exposed will be offered complimentary credit monitoring services.

The HHS’ Office for Civil Rights breach portal indicates up to 35,592 individuals were affected.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

East Paris Internal Medicine Associates Discovers Insider Breach

East Paris Internal Medicine Associates, a Grand Rapids, MI-based medical group, has discovered an insider breach involving the protected health information of 5,239 patients. On or around October 4, 2024, the medical group learned that a now-former employee had sent unencrypted emails to a personal email account on three occasions on May 11, 2023, June 13, 2024, and October 2, 2024, that contained patient data, resulting in a breach of HIPAA email rules. The investigation also revealed the employee had connected a thumb drive to their work computer and downloaded a file that potentially contained patient data. The employee was asked to hand over the thumb drive but refused.

The investigation confirmed that the employee took information such as patient names, phone numbers, medical record numbers, service dates, diagnosis codes and descriptions, procedure codes and descriptions, billing provider names, service provider names, primary care provider names, health plan names, and the amount paid for the services provided. Internal controls are being reviewed and policies and procedures relating to protected health information are being reinforced with staff members.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist