DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MD: Complete Wellness notifies 600 patients after employee misconduct results in lost PHI

Posted on January 20, 2017 by Dissent

On January 9, Complete Wellness, a treatment center in Baltimore for those with mental health issues or substance abuse, posted a Warning of Potential Privacy Violation on their web site.

The warning described an incident in which an employee – without authorization – copied patient files to a flash drive, and the flash drive was then lost. The incident affected 600 patients of two of the center’s providers.

The employee was terminated and Complete Wellness has taken steps to prevent a recurrence of this type of problem. They have also reported the incident to HHS.

The following is their notification:

Complete Wellness is committed to patient privacy. We take patient privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue if you were a patient of Leslie Poff, CRNP or Durwood Whitten, PhD.

We have learned that the personal information you provided in you initial paperwork, including name, address, phone numbers, email address, birthdate, age, social security number, languages spoken, emergency contact, level of education, employer information, primary care physician, list of medications at admission, list of allergies, ethnicity, race, marital status, hurricane victim status, living situation, military service, arrest history, and hearing or vision difficulties, may have been compromised.

On November 28, 2016, it was discovered that an employee of Complete Wellness copied a large number of patient demographic files onto a flash drive without authorization. Since then, we have been unable to locate the flash drive. However, we have not received any indication that the information has been accessed or used by an unauthorized individual.

As a result of the incident described above, Complete Wellness has taken the following actions:

  • Patient privacy training has been required for all administration and clinical staff members.
  • Technology has been adopted that eliminates the need to “transport” records.
  • Technology has been adopted to ensure proper encryption of all patient information.
  • Policies and procedures have been updated to ensure the present situation does not arise again.
  • Company leadership has been involved in several ongoing discussions to determine actions to address the current incident and to prevent future incidents.
  • The employee involved in the incident has been terminated.

We are keenly aware of how important your personal information is to you.  We strongly recommend that you contact the three credit bureaus listed below and place a “Fraud Alert” on your credit report. This service is provided free by the credit bureau agencies. For your protection you will need to verify your identity when you call.

Experian (Experian.com)               (888) 397 3742

Equifax (Equifax.com)                    (888) 766-0008

TransUnion (TransUnion.com)     (877) 322-8228

We understand that this may pose an inconvenience to you. We sincerely apologize and regret that this situation has occurred. Complete Wellness is committed to providing quality care, including protecting your personal information, and we want to assure you that we have policies and procedures to protect your privacy. If you have any questions, please contact 410-575-3252.


Related:

  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Michigan ‘ATM jackpotting’: Florida men allegedly forced machines to dispense $107K
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Missouri Adopts New Data Breach Notice Law
  • Theft from Glasgow’s Queen Elizabeth University Hospital sparks probe
Category: Health DataInsiderU.S.

Post navigation

← Former Eastern Health employee charged in privacy breach
Catholic Charities of Baltimore Notifies Clients of Potential Security Incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Minnesota National Guard deployed; St. Paul declares state of emergency in response to cyberattack
  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance
  • Wiretap Suits Pit Old Privacy Laws Against New AI Technology
  • Action against tiny Scottish charity sparks huge ICO row
  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.