Skip to content

Monroe Operations

Disclosed Aug 17, 20188 years ago1,165 affectedConfirmed

Official notice

On June 20, 2018, the covered entity (CE), Monroe Operations, LLC d/b/a Newport Academy and Center for Families, discovered that an employee’s email account was phished on or about February 22, 2018, and the hacker set an automatic forwarding rule in the employee’s email inbox. Upon discovery, the CE immediately terminated the forwarding rule and changed the email account password. The CE identified one spreadsheet in the employee’s email account that contained the protected health information (PHI) of 1,165 individuals, including demographic and health insurance information, dates of admission, and medical record numbers. The CE provided breach notification to HHS and the affected individuals; media notification was not required. In response to the breach, the CE adopted, revised, and implemented Security Rule and Breach Notification policies and procedures, performed a risk analysis, implemented a safeguard requiring employees to update their passwords regularly, and assigned a staff member the responsibility for ensuring employee participation in HIPAA training. OCR provided technical assistance on automating review of the CE's computer system and the importance of regular HIPAA

What is known

People affected1,165 (as reported to HHS)
DisclosedAug 17, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Monroe Operations (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 17, 20181,165
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Monroe Operations

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.