Mt. Carmel Behavioral Healthcare disclosed email breach exposing patient data

Organization
Mt. Carmel Behavioral Healthcare
Exploit
Phishing
Industry
Healthcare

Mt. Carmel Behavioral Healthcare, a Columbus, Ohio provider of behavioral health and addiction treatment services, disclosed that an unauthorized party had gained access to a single employee email account. The provider said the account was accessed on June 11 and June 12, 2024, and that it discovered the intrusion on June 12.

Mt. Carmel secured the account and engaged third party cybersecurity specialists to determine what the mailbox contained. A review of the messages and attachments found personal and clinical information belonging to patients, including names in combination with one or more of dates of birth, addresses, medical record numbers, patient account numbers, health insurance information, and diagnosis or treatment information. Mt. Carmel said that for a small number of patients the information also included Social Security numbers.

The provider filed a breach report with the US Department of Health and Human Services Office for Civil Rights on August 30, 2024, and mailed individual notification letters between August 9 and August 30, 2024. Neither the provider nor the outlets covering the incident published a confirmed total for the number of patients involved.

Reporting on the incident attributed the compromise to a phishing attack against the employee. Mt. Carmel recommended that affected patients review the statements they receive from their healthcare providers and health insurance plans and contact the provider or plan about any services they did not receive. It offered complimentary credit monitoring and identity protection to individuals whose Social Security numbers were involved.

Sources