Skip to content

Memorial Healthcare System

Disclosed Oct 30, 201411 years ago1,782 affectedConfirmed

Official notice

An employee of the covered entity (CE) sent a group email to current and former patients inviting them to a cancer awareness event and mistakenly failed to mask the recipients' email addresses. This breach affected the protected health information (PHI) of 1,782 individuals by exposing names and an implicit indication that they may have received cancer treatment. The CE recalled the email and immediately investigated the breach. The CE provided breach notification to HHS, affected patients, and the media, and posted substituted notice on its website. The CE established a call center to answer questions for its patients. The CE counseled the involved employee, and the employee’s supervisor reinforced to all department employees instructions regarding the use of group emails and the importance of keeping patients’ emails confidential. The CE reviewed and revised its privacy program in March 2015 and September 2015, which included guidelines for security of electronic PHI/email. In addition, the CE confirmed that it uses an encryption program to ensure the security and integrity of data. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected1,782 (as reported to HHS)
DisclosedOct 30, 2014
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 30, 20141,782
HHS archivetotalOct 31, 20141,782

Other breaches at Memorial Healthcare System

BreachAffected
Disclosed Apr 13, 2012Apr 13, 201214 years agoLost or stolen device106K
History of this record
  • 2026-09-25 · disclosed: 2014-10-31 to 2014-10-30 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Memorial Healthcare System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.