VNA Home Health and Hospice
Disclosed Mar 17, 20215 years ago517 affectedConfirmed
The covered entity (CE), VNA Home Health and Hospice, reported that an employee forgot to use the blind carbon copy function when sending out a mass email. This breach affected the electronic protected health information (ePHI) of approximately 517 individuals. The ePHI involved included names, email addresses, and treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE sanctioned the responsible workforce member and retrained staff on the proper methods of safeguarding ePHI when sending mass emails. Following the breach, OCR provided the CE with technical assistance.
What is known
| People affected | 517 (as reported to HHS) |
|---|---|
| Disclosed | Mar 17, 2021 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): VNA Home Health and Hospice (Healthcare Provider, MO)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 17, 2021 | 517 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.