Mississippi State Department of Health
Disclosed Mar 26, 20188 years ago30,799 affectedConfirmed
The covered entity (CE), the Mississippi State Department of Health, discovered that an employee accidentally sent an email on January 25, 2018, to contractors working on a joint project with an attached spreadsheet which the employee did not know contained the protected health information (PHI) of 30,799 individuals. The PHI in the spreadsheet included names, identification numbers, dates of birth, social security numbers, and sexually transmitted disease laboratory test results from 2017. The contractors confirmed that they did not retain or share the PHI. While the CE and the recipient of the email utilize transmission encryption protocols when sending emails, the CE was unable to confirm that the recipient email server accepted the email in encrypted format. There is no indication that the email had been intercepted. The CE provided timely breach notification to HHS, affected individuals, and the media. In response to the breach, the CE sanctioned the employees at fault and provided onsite HIPAA training to employees. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.
What is known
| People affected | 30,799 (as reported to HHS) |
|---|---|
| Disclosed | Mar 26, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mississippi State Department of Health (Healthcare Provider, MS)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 26, 2018 | 30,799 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.