Skip to content

Northwest Behavioral Healthcare Services

Disclosed Jul 27, 20179 years ago500 affectedConfirmed

Official notice

National Behavioral Healthcare Services, the covered entity (CE), reported that one of its workforce members inadvertently emailed a spreadsheet containing protected health information (PHI) to one patient’s parent. The breach (which was initially reported as affecting more than 500) affected 498 individuals (patients and their guardians) and included names, birthdates, contact information, insurance company identification, and other identifying information. The CE provided breach notification to HHS and affected individuals. Following the breach, the CE conducted an investigation, counseled and retrained its workforce members and implemented safeguards, including placing additional restrictions on the use and disclosure of PHI. As a result of OCR’s investigation, the CE reviewed its policies and procedures, and revised its policies for using and safeguarding spreadsheet information. As of November 2017 the CE ceased doing business.

What is known

People affected500 (as reported to HHS)
DisclosedJul 27, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 27, 2017500
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Northwest Behavioral Healthcare Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.