Cabinet for Health and Family Services, Department for Community Based Services
Disclosed Sep 19, 201214 years ago2,500 affectedConfirmed
An employee’s email account generated spam email which may have caused an unintentional release of protected health information (PHI) held by the Kentucky Cabinet for Health and Family Services (CFHS), Department for Community Based Services, the covered entity (CE). The CE provided breach notification to HHS, affected individuals, and the media, and posted a copy of its press release on the CHFS website with a toll-free number. As a result of OCR’s investigation, the CE required workforce members to sign an agreement to ensure that they understand their role in safeguarding PHI, including safeguarding from phishing attacks. The CE created a security video that all new hires are required to view and that is used for re-training of current staff. In addition, OCR obtained the CE’s HIPAA policies and procedures which complied with the requirements of the Privacy and Security Rules as well as the Breach Notification Rule.
What is known
| People affected | 2,500 (as reported to HHS) |
|---|---|
| Disclosed | Sep 19, 2012 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Cabinet for Health and Family Services, Department for Community Based Services (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 19, 2012 | 2,500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Cabinet for Health and Family Services, Department for Community Based Services