25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Greater Cincinnati Behavioral Health Services Reports 62,000-Record Data Breach

Greater Cincinnati Behavioral Health Services (GCBHS) fell victim to a cyberattack on December 10, 2023, that caused network disruption and prevented access to some of its IT systems. Immediate action was taken to contain the incident and third-party cybersecurity experts were engaged to investigate and assist with the breach response.

GCBHS said the forensic investigation is ongoing but evidence has been found that indicates an unauthorized third party accessed files containing patient information. The files are still being reviewed and notifications will be issued when that process has been completed. GCBHS said the compromised data includes names, demographic information, dates of birth, Social Security numbers, driver’s license numbers, medical information, and healthcare information. GCBHS said it has implemented additional security tools and will be offering the affected individuals complimentary credit monitoring and identity theft protection services. The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 50,000 patients.

UPDATE: September 13, 2024

GCBHS has recently notified the Maine Attorney General about the breach, which was reported as affecting 62,036 individuals, including 3 Maine residents. The OCR breach portal still shows the incident (reported on February 2, 2024) as involving the protected health information of 50,000 individuals. GCBHS said it completed its file review on May 8, 2024, and mailed its first wave of 60,080 notifications on June 12, 2024. A second wave of notifications was mailed on September 10, 2024, to 1,557 individuals. Notifications could not be mailed to 399 individuals as there was no address information.

Individuals affected had one or more of the following exposed along with their name: date of birth, driver’s license/state ID, Social Security number, license plate/VIN vehicle ID, health insurance policy plan/policy number, and other personally identifiable health information (such as Medicare/Medicaid number, cost of treatment/insurance, healthcare provider name, treatment location,  patient ID number, diagnosis/treatment/procedure, prescription drugs taken/written, medical history/allergies, medical records number, date of admission/treatment, and/or test results/images/vital signs). Complimentary credit monitoring services have been offered. The DragonForce ransomware group claimed responsibility for the attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UPDATE: October 23, 2025

A settlement has been agreed to resolve class action litigation stemming from the data breach. Further information is available in this post.

Bay Area Heart Center Affected by Cyberattack on Business Associate

Bay Area Heart Center in Florida has been affected by a cyberattack and data breach at its business associate, Bowden Barlow Law, which provides debt recovery services. The law firm conducted a forensic investigation which confirmed that the protected health information of 11,709 Bay Area Heart Center patients was compromised in the attack. The impacted data was limited to names, addresses, full and partial Social Security Numbers, dates of service, limited claims data, and insurance policy numbers. Bowden Barlow Law has made cybersecurity improvements and is offering the affected individuals complimentary credit monitoring services for 12 months.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist