The covered entity (CE), Managed Health Services, reported that a contract employee improperly sent Excel documents containing protected health information (PHI) to his personal email account. This breach affected 5,500 individuals. The PHI involved included names, addresses, dates of birth, diagnoses/conditions, clinical information, and medications prescribed. The CE notified HHS, affected individuals, and the media. As a result of this breach, the CE sanctioned the employee and implemented additional technical safeguards to further protect its PHI. As a result of OCR’s investigation, the CE providing focused training to its employees on the protection of PHI and the minimum necessary requirement of the HIPAA Privacy Rule. OCR obtained assurances that the CE implemented the corrective actions noted.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 5500 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Managed Health Services, reported that a contract employee improperly sent Excel documents containing protected health information (PHI) to his personal email account. This breach affected 5,500 individuals. The PHI · backfill source