Progressions Behavioral Health Services
Disclosed Jun 25, 20188 years ago1,303 affectedConfirmed
An unauthorized user gained access to employees’ email account after a phishing attack and set the employees’ emails to automatically forward to an external account. The breach involved the protected health information (PHI) of 1,303 individuals and included clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE implemented multi-factor authentication for its email accounts and implemented a new privacy and security training program for employees. Additionally, OCR ensured that the CE completed an appropriate risk analysis after the breach.
What is known
| People affected | 1,303 (as reported to HHS) |
|---|---|
| Disclosed | Jun 25, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Progressions Behavioral Health Services (Healthcare Provider, PA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 25, 2018 | 1,303 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.