25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Email Accounts Compromised at Children’s Minnesota and the LA County Dept. of Mental Health

Email security breaches have been reported by Children’s Healthcare in Minnesota and the Los Angeles County Department of Mental Health that exposed patient information.

Children’s Health Care, Minnesota

Children’s Health Care, a children’s hospital in Minneapolis, MN, has discovered that patients’ protected health information has been exposed in an email security incident that was detected on March 13, 2024. Suspicious activity was identified in its email system and the forensic investigation confirmed that there had been unauthorized access to two employee email accounts between February 29, 2024, and March 25, 2024. The review of the emails and attachments is ongoing; however, it has been determined that patient information related to the surgical services department was stored in those accounts.

The information potentially compromised in the attack included names, addresses, dates of birth, insurance carrier names, medical record numbers, provider names, treatment cost information, and/or limited treatment information related to care received at Children’s Minnesota. The compromised accounts did not contain any financial account, credit card information, or Social Security numbers. While patient data has been exposed, Children’s Minnesota is unaware of any misuse of that information.

The breach has recently been reported to the HHS’ Office for Civil Rights as affecting 7,260 patients. Those patients will be notified by mail in the coming weeks. Children’s Minnesota already provides cybersecurity and privacy training to its workforce and will continue to do so and will be implementing additional safeguards to improve email security.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

LA County Department of Mental Health, California

The LA County Department of Mental Health has fallen victim to a phishing attack that resulted in unauthorized access to an employee’s email account and the protected health information of 1,598 patients. The attack occurred on March 20, 2024, via a compromised employee email account at an unnamed external entity. The attacker used the account to send a phishing email to an employee of the department, who responded believing the email to be genuine and disclosed their account credentials.

The account review confirmed that names, addresses, telephone numbers, dates of birth, medical record numbers, and Social Security numbers were potentially compromised. The Department said it had extensive measures in place to protect against this type of attack but those safeguards were circumvented due to the exploitation of a vulnerability in Microsoft’s Office 365 multifactor authentication.

After disabling the affected accounts, the Office 365 and multifactor authentication credentials were reset, and security policies, procedures, and controls have been reviewed and updated. The Department has notified Microsoft about the vulnerability and has implemented additional controls to better protect against these types of attacks in the future. The review was completed on May 16, 2024, and individual notifications were mailed on May 20, 2024.

Information on Email Compliance

HIPAA compliance for email

Does HIPAA prevent patient names from being emailed?

HIPAA compliant email providers

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Prevent HIPAA Email Violations

Avoid the common misunderstandings and implementation errors relating to HIPAA email.

Learn more