DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MD: Complete Wellness notifies 600 patients after employee misconduct results in lost PHI

Posted on January 20, 2017 by Dissent

On January 9, Complete Wellness, a treatment center in Baltimore for those with mental health issues or substance abuse, posted a Warning of Potential Privacy Violation on their web site.

The warning described an incident in which an employee – without authorization – copied patient files to a flash drive, and the flash drive was then lost. The incident affected 600 patients of two of the center’s providers.

The employee was terminated and Complete Wellness has taken steps to prevent a recurrence of this type of problem. They have also reported the incident to HHS.

The following is their notification:

Complete Wellness is committed to patient privacy. We take patient privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue if you were a patient of Leslie Poff, CRNP or Durwood Whitten, PhD.

We have learned that the personal information you provided in you initial paperwork, including name, address, phone numbers, email address, birthdate, age, social security number, languages spoken, emergency contact, level of education, employer information, primary care physician, list of medications at admission, list of allergies, ethnicity, race, marital status, hurricane victim status, living situation, military service, arrest history, and hearing or vision difficulties, may have been compromised.

On November 28, 2016, it was discovered that an employee of Complete Wellness copied a large number of patient demographic files onto a flash drive without authorization. Since then, we have been unable to locate the flash drive. However, we have not received any indication that the information has been accessed or used by an unauthorized individual.

As a result of the incident described above, Complete Wellness has taken the following actions:

  • Patient privacy training has been required for all administration and clinical staff members.
  • Technology has been adopted that eliminates the need to “transport” records.
  • Technology has been adopted to ensure proper encryption of all patient information.
  • Policies and procedures have been updated to ensure the present situation does not arise again.
  • Company leadership has been involved in several ongoing discussions to determine actions to address the current incident and to prevent future incidents.
  • The employee involved in the incident has been terminated.

We are keenly aware of how important your personal information is to you.  We strongly recommend that you contact the three credit bureaus listed below and place a “Fraud Alert” on your credit report. This service is provided free by the credit bureau agencies. For your protection you will need to verify your identity when you call.

Experian (Experian.com)               (888) 397 3742

Equifax (Equifax.com)                    (888) 766-0008

TransUnion (TransUnion.com)     (877) 322-8228

We understand that this may pose an inconvenience to you. We sincerely apologize and regret that this situation has occurred. Complete Wellness is committed to providing quality care, including protecting your personal information, and we want to assure you that we have policies and procedures to protect your privacy. If you have any questions, please contact 410-575-3252.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
Category: Health DataInsiderU.S.

Post navigation

← Former Eastern Health employee charged in privacy breach
Catholic Charities of Baltimore Notifies Clients of Potential Security Incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.