A workforce member of Jersey City Medical Center sent an email with a spreadsheet attachment that contained 1,447 patients’ protected health information (PHI) to an unintended recipient. The spreadsheet included patients’ names, health insurance payors, dates of admission and discharges, department locations where medical services were received, and individuals’ account numbers. The covered entity provided breach notification to HHS, the media, and the affected individuals, and offered 12 months of identity protection services. Following the breach, the entity sanctioned and retrained the sender of the email and provided HIPAA training to its workforce.
Affected (this filing): 1,447