Forrest General Hospital
Disclosed Feb 1, 20188 years ago1,670 affectedConfirmed
Horne CPAs & Business Advisors, a business associate (BA) of Forrest General Hospital (CE), discovered that a staff member’s email account was sending out suspicious emails after being compromised in a phishing attack. The BA investigated the incident, and determined that an email attachment to one of the emails in the compromised account contained the protected health information (PHI) of 1,671 of the CE’s patients. The types of breached PHI included names, Medicaid numbers, dates of service, dates of birth, patient account numbers, and Social Security numbers. The BA notified the CE, and worked with the CE to meet the requirements of the Breach Notification Rule. The BA provided breach notification to the affected individuals and the media. The CE provided notice to HHS and on its website. The BA sanctioned the employee involved and, in response to this incident and OCR’s investigation, the BA implemented several technical security improvements. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,670 (as reported to HHS) |
|---|---|
| Disclosed | Feb 1, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Forrest General Hospital (Healthcare Provider, MS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 1, 2018 | 1,670 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.