DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MD: Complete Wellness notifies 600 patients after employee misconduct results in lost PHI

Posted on January 20, 2017 by Dissent

On January 9, Complete Wellness, a treatment center in Baltimore for those with mental health issues or substance abuse, posted a Warning of Potential Privacy Violation on their web site.

The warning described an incident in which an employee – without authorization – copied patient files to a flash drive, and the flash drive was then lost. The incident affected 600 patients of two of the center’s providers.

The employee was terminated and Complete Wellness has taken steps to prevent a recurrence of this type of problem. They have also reported the incident to HHS.

The following is their notification:

Complete Wellness is committed to patient privacy. We take patient privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue if you were a patient of Leslie Poff, CRNP or Durwood Whitten, PhD.

We have learned that the personal information you provided in you initial paperwork, including name, address, phone numbers, email address, birthdate, age, social security number, languages spoken, emergency contact, level of education, employer information, primary care physician, list of medications at admission, list of allergies, ethnicity, race, marital status, hurricane victim status, living situation, military service, arrest history, and hearing or vision difficulties, may have been compromised.

On November 28, 2016, it was discovered that an employee of Complete Wellness copied a large number of patient demographic files onto a flash drive without authorization. Since then, we have been unable to locate the flash drive. However, we have not received any indication that the information has been accessed or used by an unauthorized individual.

As a result of the incident described above, Complete Wellness has taken the following actions:

  • Patient privacy training has been required for all administration and clinical staff members.
  • Technology has been adopted that eliminates the need to “transport” records.
  • Technology has been adopted to ensure proper encryption of all patient information.
  • Policies and procedures have been updated to ensure the present situation does not arise again.
  • Company leadership has been involved in several ongoing discussions to determine actions to address the current incident and to prevent future incidents.
  • The employee involved in the incident has been terminated.

We are keenly aware of how important your personal information is to you.  We strongly recommend that you contact the three credit bureaus listed below and place a “Fraud Alert” on your credit report. This service is provided free by the credit bureau agencies. For your protection you will need to verify your identity when you call.

Experian (Experian.com)               (888) 397 3742

Equifax (Equifax.com)                    (888) 766-0008

TransUnion (TransUnion.com)     (877) 322-8228

We understand that this may pose an inconvenience to you. We sincerely apologize and regret that this situation has occurred. Complete Wellness is committed to providing quality care, including protecting your personal information, and we want to assure you that we have policies and procedures to protect your privacy. If you have any questions, please contact 410-575-3252.

Category: Health DataInsiderU.S.

Post navigation

← Former Eastern Health employee charged in privacy breach
Catholic Charities of Baltimore Notifies Clients of Potential Security Incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach
  • ‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential abuse survivors’ addresses
  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
  • Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach
  • Hacker who breached communications app used by Trump aide stole data from across US government
  • Massachusetts hacker to plead guilty to PowerSchool data breach (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.