Carolinas Medical Center - Randolph
Disclosed Dec 7, 201213 years ago5,600 affectedConfirmed
The covered entity (CE), Carolina’s Medical Center, discovered that a physician had responded to a phishing email and provided her password to a third party, causing all of the physician’s emails to be forwarded to a third party. The forwarded emails included protected health information (PHI) regarding 5,600 individuals. The PHI in the emails included names, dates of birth, medications, treatment information, social security numbers (for 5 patients), dates of service, addresses, names of providers, admission/discharge dispositions and dates, and internal medical record and account numbers. Following the breach, CE improved administrative and technical safeguards by terminating auto-forwarding capabilities and implementing an alert for remote system accesses that originate from a foreign country. The CE also trained employees on identifying social engineering schemes. OCR obtained assurances that the corrective actions were taken.
What is known
| People affected | 5,600 (as reported to HHS) |
|---|---|
| Disclosed | Dec 7, 2012 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Carolinas Medical Center - Randolph (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 7, 2012 | 5,600 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.