Unsecured email cause of Memphis breach
The Regional Medical Center in Memphis is notifying physical therapy patients of a HIPAA breach after an employee sent out three unsecure emails containing the protected health information and Social Security numbers of nearly 1,200 patients.
On three occasions, October 29, 2012, November 1, 2012, and February 4, 2013, an employee sent the unsecured emails and the error was discovered on March 15. The unsecured emails included the names, Social Security numbers, dates of birth, account numbers, phone numbers and outpatient physical therapy services data of patients treated between May 2012 and January 2013.
"The medical center has been and will continue to work closely with the company that received the emails, and it is believed the emails were deleted and not further used or disclosed at the time of the incident," the notification read. "The medical center believes this was an innocent employee mistake and has not received any indication that patient information has been used or further disclosed in an inappropriate manner by anyone."