West Cecil Health Center
Disclosed Feb 17, 20233 years ago1,136 affectedConfirmed
The covered entity (CE), West Cecil Health Center, reported that its business associate’s (BA) scheduling platform had a code installed which compromised the protected health information (PHI) of 1,136 individuals. The PHI involved included names, dates of birth, addresses, clinical, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA removed the code, engaged a specialized cybersecurity firm to conduct a forensic investigation, and provided complimentary credit monitoring services to affected individuals.
What is known
| People affected | 1,136 (as reported to HHS) |
|---|---|
| Disclosed | Feb 17, 2023 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): West Cecil Health Center (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 17, 2023 | 1,136 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.