Monroe Operations
Disclosed Aug 17, 20188 years ago1,165 affectedConfirmed
On June 20, 2018, the covered entity (CE), Monroe Operations, LLC d/b/a Newport Academy and Center for Families, discovered that an employee’s email account was phished on or about February 22, 2018, and the hacker set an automatic forwarding rule in the employee’s email inbox. Upon discovery, the CE immediately terminated the forwarding rule and changed the email account password. The CE identified one spreadsheet in the employee’s email account that contained the protected health information (PHI) of 1,165 individuals, including demographic and health insurance information, dates of admission, and medical record numbers. The CE provided breach notification to HHS and the affected individuals; media notification was not required. In response to the breach, the CE adopted, revised, and implemented Security Rule and Breach Notification policies and procedures, performed a risk analysis, implemented a safeguard requiring employees to update their passwords regularly, and assigned a staff member the responsibility for ensuring employee participation in HIPAA training. OCR provided technical assistance on automating review of the CE's computer system and the importance of regular HIPAA
What is known
| People affected | 1,165 (as reported to HHS) |
|---|---|
| Disclosed | Aug 17, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Monroe Operations (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 17, 2018 | 1,165 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.