Skip to content

Baptist Health

Disclosed May 7, 20188 years ago3,453 affectedConfirmed

Official notice

A physician of the covered entity (CE), Baptist Health, stored patients’ protected health information (PHI) on a cloud-based file sharing application without a business associate (BA) contract in place. The PHI potentially affected included the names, dates of birth, and treatment information of approximately 3,453 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE improved safeguards, updated its policies and procedures, and trained users of its electronic health record system on better practices to protect PHI. OCR obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected3,453 (as reported to HHS)
DisclosedMay 7, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Baptist Health (Healthcare Provider, AR)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMay 7, 20183,453

Other breaches at Baptist Health

BreachAffected
Disclosed Sep 30, 2024Sep 30, 20241 year ago1,823
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Baptist Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.