Skip to content

Progressions Behavioral Health Services

Disclosed Jun 25, 20188 years ago1,303 affectedConfirmed

Official notice

An unauthorized user gained access to employees’ email account after a phishing attack and set the employees’ emails to automatically forward to an external account. The breach involved the protected health information (PHI) of 1,303 individuals and included clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE implemented multi-factor authentication for its email accounts and implemented a new privacy and security training program for employees. Additionally, OCR ensured that the CE completed an appropriate risk analysis after the breach.

What is known

People affected1,303 (as reported to HHS)
DisclosedJun 25, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 25, 20181,303
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Progressions Behavioral Health Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.