Skip to content

Morehead Memorial Hospital

Disclosed Sep 15, 20179 years ago66,000 affectedConfirmed

Official notice

In late June 2017, employees at Morehead Memorial Hospital, the covered entity (CE), began reporting suspicious phishing emails to the information technology department. Through its contracted forensic investigator, Navigant Consulting, the CE found that two employee email accounts were compromised and protected health information (PHI) for about 66,000 individuals was exposed. The exposed PHI included treatment information, payment information, names, business reports, diagnostic information and for 1,200 individuals, their social security numbers as well. In response to the breach, the CE reset password for all employee accounts. The CE also added phishing information to employee training materials and created an internal website to improve reporting and notification of security incidents. The CE also verbally reminded employees directly involved with the compromised accounts about being vigilant and careful when email attachments. The CE provided breach notification to HHS, affected individuals, and the media, and posted substitute notice on its website. OCR obtained assurances that the CE implemented the corrective actions noted above. In response to the breach, Morehead initia

What is known

People affected66,000 (as reported to HHS)
DisclosedSep 15, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 15, 201766,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Morehead Memorial Hospital

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.