Adventist HealthCare Data Breach
Adventist HealthCare: 1,300 Patients Affected by Lost Paper Records
What happened in the Adventist HealthCare data breach?
The Adventist HealthCare data breach was reported on November 13, 2024 and affected 1,300 individuals. The breach type was Loss involving Paper/Films. This breach occurred in Maryland. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Adventist HealthCare Breach Details
Adventist HealthCare Data Breach Report
Incident Overview
Adventist HealthCare, a healthcare organization operating in Maryland, reported a data breach affecting 1,300 individuals on November 13, 2024. The breach involved the loss of physical paper records and films, representing a traditional but still significant threat to patient privacy in the healthcare industry. Unlike digital breaches that often involve sophisticated hacking techniques, this incident demonstrates how physical security lapses can expose sensitive protected health information (PHI) to unauthorized access or misuse.
Discovery and Response Timeline
The breach was discovered and reported to the Maryland Attorney General's office on November 13, 2024, indicating that Adventist HealthCare identified the missing materials and initiated their breach response protocol in accordance with HIPAA Breach Notification Rule requirements. The organization's discovery process likely involved inventory reconciliation or staff identification of missing records during routine operations. Upon discovery, Adventist HealthCare would have been required to conduct a risk assessment to determine whether the loss constituted a reportable breach under HIPAA—a determination that resulted in notification to affected individuals. The involvement of a business associate in this breach suggests that the lost materials may have been in transit, storage, or processing by a third-party vendor, which adds complexity to the investigation and responsibility chain.
Specific Details of the Loss
The breach involved the loss of paper documents and films, which are physical media commonly used in healthcare settings for patient records, imaging results, and clinical documentation. Paper records and films represent a significant portion of healthcare data storage, particularly in established healthcare systems that may maintain hybrid digital-paper record systems. The loss of these materials could have occurred during transport between facilities, during storage at off-site locations, or through misplacement within the organization's physical infrastructure. Physical media losses are particularly concerning because once lost, there is typically no audit trail to determine who may have accessed the information or how it might be used. Unlike digital breaches where forensic analysis can sometimes identify unauthorized access patterns, physical losses create uncertainty about the ultimate disposition of the materials and the scope of potential exposure.
Organizational Context
Adventist HealthCare is a significant healthcare provider in Maryland, operating multiple facilities and providing comprehensive healthcare services to the region. As a healthcare system with sufficient scale to employ business associates for record management and processing, the organization handles substantial volumes of patient information across multiple locations and operational units. The involvement of a business associate in this breach indicates that Adventist HealthCare utilizes third-party vendors for functions such as records storage, document imaging, transportation, or archival services—a common practice among healthcare systems seeking to optimize operational efficiency. This arrangement, while operationally beneficial, creates additional responsibility for ensuring that business associates maintain adequate physical security controls over patient information.
Patient Impact and Notification
Approximately 1,300 individuals were affected by this breach, representing patients whose records were among the lost materials. These patients would have received breach notification letters from Adventist HealthCare in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The notification would have included information about the nature of the breach, the types of information involved, steps the organization is taking to investigate and prevent future incidents, and recommended actions patients should take to protect themselves. Given the November 13, 2024 submission date, affected individuals would have been notified by mid-January 2025 at the latest, though notification likely occurred sooner.
Industry Context and HIPAA Implications
Physical loss of healthcare records remains a persistent vulnerability in the healthcare industry despite decades of HIPAA enforcement. The HIPAA Security Rule requires covered entities and business associates to implement physical safeguards including facility access controls, workstation security, and device and media controls to protect electronic PHI, while the Privacy Rule extends protections to all PHI regardless of format. Physical losses of paper records and films represent failures in the device and media controls component of the Security Rule, which specifically addresses the physical security of storage media containing PHI. According to HHS breach notification data, losses of physical media account for a significant percentage of healthcare breaches annually, often involving materials lost during transport, at off-site storage facilities, or through inadequate inventory controls. The involvement of a business associate in this incident underscores the importance of Business Associate Agreements (BAAs) that clearly delineate responsibility for maintaining physical security controls and establishing breach notification procedures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Adventist HealthCare Breach
Monitor credit reports and financial accounts closely for signs of identity theft or fraudulent activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized credit applications
Review medical records and explanation of benefits statements from your healthcare providers and insurance company for any unauthorized services or claims; contact providers immediately if you identify suspicious activity
Monitor for unsolicited contact from healthcare providers or pharmacies regarding services or prescriptions you did not authorize, which could indicate medical identity theft
Consider enrolling in credit monitoring or identity theft protection services if offered by Adventist HealthCare as part of their breach response; these services can provide early warning of suspicious activity
Retain copies of breach notification letters and documentation of any fraudulent activity for your records and potential future claims; report any confirmed fraud to law enforcement and the FTC
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Maryland Breaches
Search all breaches reported in Maryland
Technical Notes
Adventist HealthCare Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Adventist HealthCare