25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Email Breach at Guam Seventh-Day Adventist Clinic Affects 56,000 Individuals

Email accounts have been compromised at Guam Seventh-Day Adventist Clinic and Mount Carmel Behavioral Health. The attack on Guam Seventh-Day Adventist Clinic involved the protected health information of 56,635 individuals and result in a breach of HIPAA email rules.

Guam Seventh-Day Adventist Clinic

Guam Seventh-Day Adventist Clinic in Tamuning, Guam, has recently notified 56,635 individuals about a breach of a limited number of employee email accounts. The email accounts were breached between January 23, 2023, and February 3, 2023. A breach notice was uploaded to its website to inform patients about the breach; however, notifications are only now being mailed due to the time taken to investigate the incident. On August 6, 2024, the clinic confirmed that personal and protected health information had been exposed and potentially acquired by unauthorized individuals, although no misuse of the affected information has been identified.

The types of data involved varied from individual to individual and may have included names along with one or more of the following: address, phone number, email address, date of birth, financial account information ( including account and routing number), payment card information, username and password, driver’s license number, government identification number, vehicle identification number, passport number, Social Security number, taxpayer ID number, mother’s maiden name, medical record number, patient ID account number, medical diagnosis and treatment information, and health insurance information.

Guam Seventh-Day Adventist Clinic has implemented additional cybersecurity safeguards, improved its cybersecurity policies, procedures, and protocols, and has enhanced its employee cybersecurity training program.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Mount Carmel Behavioral Health

Mount Carmel Behavioral Health in Columbus, OH, has discovered unauthorized access to an employee email account. The email account breach was identified on June 12, 2024, a day after the account was breached. Immediate action was taken to secure the account to prevent further unauthorized access, and a forensic investigation was conducted to determine the extent of the breach.

Third-party cybersecurity experts confirmed the email account was accessed by an unauthorized individual between June 11, 2024, and June 12, 2024. During that time, certain emails and attachments containing patient data were viewed and potentially copied. No other email accounts were compromised in the incident.

The review is ongoing, but it has been determined that the types of information involved included names, dates of birth, addresses, medical record numbers, patient account numbers, health insurance information, diagnoses and/or treatment information. A limited number of patients also had their Social Security numbers exposed.

Notification letters were mailed to the affected individuals between August 9, 2024, and August 30, 2024, and complimentary credit monitoring and identity protection services were offered to individuals whose Social Security numbers were exposed. On August 30, 2024, the breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 500 individuals.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Prevent HIPAA Email Violations

Avoid the common misunderstandings and implementation errors relating to HIPAA email.

Learn more