Northwest Behavioral Healthcare Services
Disclosed Jul 27, 20179 years ago500 affectedConfirmed
National Behavioral Healthcare Services, the covered entity (CE), reported that one of its workforce members inadvertently emailed a spreadsheet containing protected health information (PHI) to one patient’s parent. The breach (which was initially reported as affecting more than 500) affected 498 individuals (patients and their guardians) and included names, birthdates, contact information, insurance company identification, and other identifying information. The CE provided breach notification to HHS and affected individuals. Following the breach, the CE conducted an investigation, counseled and retrained its workforce members and implemented safeguards, including placing additional restrictions on the use and disclosure of PHI. As a result of OCR’s investigation, the CE reviewed its policies and procedures, and revised its policies for using and safeguarding spreadsheet information. As of November 2017 the CE ceased doing business.
What is known
| People affected | 500 (as reported to HHS) |
|---|---|
| Disclosed | Jul 27, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Northwest Behavioral Healthcare Services (Healthcare Provider, OR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 27, 2017 | 500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.