Skip to content

Mississippi State Department of Health

Disclosed Mar 26, 20188 years ago30,799 affectedConfirmed

Official notice

The covered entity (CE), the Mississippi State Department of Health, discovered that an employee accidentally sent an email on January 25, 2018, to contractors working on a joint project with an attached spreadsheet which the employee did not know contained the protected health information (PHI) of 30,799 individuals. The PHI in the spreadsheet included names, identification numbers, dates of birth, social security numbers, and sexually transmitted disease laboratory test results from 2017. The contractors confirmed that they did not retain or share the PHI. While the CE and the recipient of the email utilize transmission encryption protocols when sending emails, the CE was unable to confirm that the recipient email server accepted the email in encrypted format. There is no indication that the email had been intercepted. The CE provided timely breach notification to HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the employees at fault and provided onsite HIPAA training to employees. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.

What is known

People affected30,799 (as reported to HHS)
DisclosedMar 26, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 26, 201830,799
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mississippi State Department of Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.