Memorial Hospital at Gulfport
Disclosed Feb 28, 20188 years ago56,850 affectedConfirmed
On December 4, 2018 an employee in the medical records department responded to a phishing email and provided their username and password credentials. On December 6, 2018, a routine system audit log uncovered nine outside logins to the covered entity’s system from an unauthorized individual who may have accessed 30,642 patient’s protected health information (PHI), including demographic and clinical information. IT personnel secured the email account and investigated the emails within the compromised account. Following the incident, the CE implemented a multi-factor authentication requirement and trained staff on phishing. On February 15, 2019, the CE provided breach notification to HHS, the affected individuals, and to the media. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 56,850 (as reported by the organization) |
|---|---|
| Disclosed | Feb 28, 2018 |
| Happened | Dec 6, 2018 |
| Attack | Hacking |
| Data exposed | Names, Social Security numbers, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Maine Attorney General breach notice archive: Memorial Hospital at Gulfportmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Memorial Hospital at Gulfport (Healthcare Provider, MS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 28, 2018 | 1,512 |
| HHS archivetotal | Feb 15, 2019 | 30,642 |
| Maine AGresidents of ME | Jun 14, 2019 | 4 |
History of this record
- 2026-09-25 · disclosed: 2019-02-15 to 2018-02-28 · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: ["names","ssn"] to ["names","ssn","health"] · backfill source
- 2026-09-25 · disclosed: 2019-06-14 to 2019-02-15 · backfill source
- 2026-09-25 · summary: empty to On December 4, 2018 an employee in the medical records department responded to a phishing email and provided their username and password credentials. On December 6, 2018, a routine system audit log uncovered nine outside logins to the cover · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.