Equitas Health (Ohio healthcare provider) reported to HHS OCR that an employee fell victim to an email phishing scheme exposing ePHI of 569 individuals. Compromised data included names, dates of birth, addresses, Social Security numbers, diagnoses, and prescribed medications. The CE notified HHS, affected individuals, and the media; implemented additional administrative, technical, and security safeguards; and retrained workforce on identifying fraudulent email. OCR obtained assurances that corrective actions were implemented.
Affected (this filing): 569