25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Catawba Valley Medical Center Phishing Attack Impacts 20,000 Patients

On August 13, 2018, Catawba Valley Medical Center (CVMC) in Hickory, NC discovered an unauthorised individual accessed the email account of a CVMC employee. Upon discovery of the email breach, steps were taken to secure the account and prevent further access and a third-party computer forensics firm was called in to assist with the investigation and determine the extent of the breach.

That investigation revealed that between July 4 and August 17, 2018, three employees’ email accounts had been compromised after the employees responded to phishing emails. Some of the emails in those accounts contained patients’ protected health information including names, dates of birth, details of medical services received at CVMC, health insurance details, and for certain patients, Social Security numbers.

No evidence was found to suggest that any emails had been accessed or copied and no information has been received to suggest patient health information has been misused in any way.

The phishing incidents have prompted CVMC to hire security experts to enhance employee education, more robust email security controls have been implemented, and CVMC will continue to upgrade hardware and software as appropriate to repel malicious threats.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All patients whose protected health information may have been compromised as a result of the email account breaches were notified by mail on October 12, 2018.

The breach summary on the HHS’ Office for Civil Rights’ breach portal indicates up to 20,000 patients have potentially been affected by the email account breaches.

Byram Healthcare Alerts Patients to Insider Breach

Byram Healthcare, a provider of medical supplies, has been informed by law enforcement that a former employee has been accused of stealing the credit card information of patients.

Byram Healthcare investigated the incident and determined that the employee had access to personal information including names, addresses, dates of birth, limited health information, and credit card numbers, but not Social Security numbers. It is unclear at this stage how many patients have been affected.

Byram Healthcare has responded to the breach by providing further training to staff on privacy and security obligations and safeguarding patients’ protected health information. Monitoring of staff has also been increased.  Affected patients were notified by mail of the privacy violation and possible theft of PHI on October 22, 2018.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist