25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Email Breaches Reported by MedStar Health, Bluebonnet Trails Community Services, Bluegrass Care Navigators

MedStar Health is notifying more than 118,000 patients about an email security incident that exposed their protected health information. Email accounts have also been compromised at Bluebonnet Trails Community Services and Bluegrass Care Navigators.

MedStar Health

MedStar Health, a non-profit healthcare provider that operates 10 hospitals in the Baltimore-Washington area, said hackers gained access to its network and may have obtained the protected health information of 183,000 patients, including names, addresses, dates of birth, dates of service, provider names, and health insurance information.

MedStar Health did not say when the unauthorized access was first detected but confirmed that the email accounts of three employees were accessed by unauthorized individuals intermittently between January 2023 and October 2023. MedStar Health said it has no reason to believe that patient data was accessed or acquired, but it was not possible to rule out data theft with a high degree of certainty. As required by HIPAA, MedStar Health had implemented technical, physical, and administrative safeguards to ensure the confidentiality of patient data, and since the breach has augmented those safeguards to prevent similar breaches in the future. The affected individuals were notified by mail on May 3, 2024.

Bluebonnet Trails Community Services

Bluebonnet Trails Community Services, a provider of mental health and developmental disabilities services in central Texas, has experienced a breach of its email environment. Unauthorized activity was detected in its email environment on or around October 4, 2023. Passwords were reset to prevent further unauthorized access, and third-party cybersecurity experts were engaged to investigate the incident. The investigation confirmed that a small number of employee email accounts had been accessed by an unauthorized third party between July 20, 2023, and October 6, 2023. The accounts were reviewed to determine the types of information that had been exposed, and that process was completed on February 26, 2024.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Bluebonnet Trails Community Services said 76,165 individuals had some of their protected health information exposed, including names in combination with one or more of the following: date of birth, Social Security number, driver’s license or state identification number, financial account number, medical information, health insurance information, full-access credentials, and government-issued identification number. Bluebonnet Trails Community Services has reviewed its policies and procedures relating to data privacy and security and has implemented additional safeguards to prevent similar incidents in the future.

Bluegrass Care Navigators

Hospice of the Bluegrass, Inc., doing business as Bluegrass Care Navigators, has reported a data security incident involving the protected health information of 2,282 individuals. The Kentucky, home healthcare provider and hospice operator identified unauthorized access to an employee’s email account on March 4, 2024. The forensic investigation found no evidence of access to its network, electronic health records, or other employee email accounts. The compromised account was reviewed and was found to contain information such as patient names and health insurance information. Bluegrass Care Navigators said it has implemented additional safeguards to improve email security.

Email breaches are commonly reported by HIPAA-regulated entities, and while it is not possible to completely eliminate risk, it is possible to reduce risk to a low and acceptable level by making your email HIPAA-compliant, providing security awareness training to the workforce and implementing phishing-resistant multi-factor authentication.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Prevent HIPAA Email Violations

Avoid the common misunderstandings and implementation errors relating to HIPAA email.

Learn more