25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Citizens Memorial Hospital Latest Victim of W-2 Phishing Scam

Another healthcare provider has announced that one of its employees has been fooled by a W-2 phishing scam. Citizens Memorial Hospital in Bolivar, MO., says a request for W-2 Form data was sent to one of its employees by email.

The employee responded to the request believing the message was legitimate and had been sent internally. W-2 Forms for all employees at the 86-bed hospital who had taxable earnings for the 2016 fiscal year were sent via email to the scammers as requested. No announcement has been made about the number of employees impacted by the incident. The hospital discovered it was the victim of a scam the following day.

The incident has been reported to both the FBI and the IRS and affected employees have been notified and offered 2 years of identity theft protection services without charge through Experian. The incident is not a HIPAA breach as HIPAA Rules do not apply to employee data.

To prevent repeat attacks, Citizens Memorial Hospital will be enhancing its data security education programs. Staff will receive further training to help them identify any further phishing scams sent via email.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The W-2 phishing scam has already claimed many victims this year. The scammers send an email to a member of the payroll/HR department requesting W-2 Form data for all employees who worked for the organization in 2016. The scammers usually impersonate the CEO/CFO and use an email address similar to that used by the targeted organization. Oftentimes, there is one letter missing from the domain part of the email address. A casual glance at the sender’s address is unlikely to reveal that the email is a scam. A careful check will reveal that the email account has been spoofed.

This type of scam was popular last tax season. There were at least 145 victims of the scam last year and tens of thousands of employees had their Social Security numbers, personal information, and earnings disclosed to tax fraudsters. Earlier this month, the IRS issued a warning to educational institutions, nonprofits, tribal organization and healthcare organizations about the W-2 phishing scam advising them to be on high alert.

Databreaches.net is tracking reports of W-2 Form phishing scams. There have already been 62 organizations that have announced they have been fooled by the W-2 phishing scam in 2017.

In addition to Citizens Memorial Hospital, the following healthcare organizations have reported that an employee responded to the scam and disclosed employee data:

  • Adventist Health, Tehachapi Valley, CA
  • Campbell County Health, WY
  • EHealthInsurance, CA
  • Point Coupee Hospital, LA
  • SouthEast Alaska Regional Health Consortium, AK

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist