Pasquotank-Camden Emergency Medical Service
Disclosed Feb 28, 20197 years ago20,420 affectedConfirmed
On December 14, 2018, Pasquotank-Camden Emergency Medical Services, the covered entity (CE), discovered that data from its administrative server where protected health information (PHI) was stored, was missing. The breach affected 40,753 individuals whose names, billing records, medical information, Social Security numbers, and dates of birth were stored on the server. The CE’s forensic investigation determined that the breach was caused by a brute force attack to its server by a hacker located in Eastern Europe. The CE restored the deleted data using a recent backup of the server. The CE sent timely media notification on December 21, 2018. Individual notification and substitute notification were not provided until February 21, 2019 and February 25, 2019, respectively. The CE offered affected individuals identity monitoring and restoration insurance for one year following the breach. In response to the breach, the CE implemented physical safeguards for its administrative office, updated software, migrated historical data to external hard drives, initiated a process to identify a new EHR software vendor, and improved safeguards for system user accounts. OCR provided technical assist
What is known
| People affected | 20,420 (as reported to HHS) |
|---|---|
| Disclosed | Feb 28, 2019 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Pasquotank-Camden Emergency Medical Service (Healthcare Provider, NC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 28, 2019 | 20,420 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Pasquotank-Camden Emergency Medical Service