Mount Carmel Behavioral Health
Disclosed Aug 30, 20242 years ago1,221 affectedConfirmed
Mount Carmel Behavioral Health, a covered entity (CE), reported that one of its employees was the target of an email phishing scheme affecting the protected health information (PHI) of 1,221 individuals. The PHI involved included names, addresses, dates of birth, Social Security numbers, diagnoses, conditions, and other treatment information. The CE notified HHS, affected individuals, and the media. The CE took several corrective actions in response to the breach including implementing multi-factor authentication and providing additional HIPAA training to its work force members.
What is known
| People affected | 1,221 (as reported to HHS) |
|---|---|
| Disclosed | Aug 30, 2024 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mount Carmel Behavioral Health (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 30, 2024 | 1,221 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.