Adventist HealthCare Data Breach
Adventist HealthCare: 1,300 Patients Affected by Lost Paper Records
What happened in the Adventist HealthCare data breach?
The Adventist HealthCare data breach was reported on November 13, 2025 and affected 1,300 individuals. The breach type was Loss involving Paper/Films. This breach occurred in Maryland. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Adventist HealthCare Breach Details
Adventist HealthCare Data Breach Report
Incident Overview
Adventist HealthCare, a healthcare provider operating in Maryland, reported a data breach affecting approximately 1,300 individuals on November 13, 2025. The breach involved the loss of paper documents and films containing protected health information (PHI). This incident represents a physical security failure rather than a cyber-based attack, highlighting the continued vulnerability of traditional paper-based medical record systems in healthcare environments. The loss occurred at an unspecified facility location within the Adventist HealthCare system, and the breach was classified as involving a business associate, suggesting that third-party vendors or contractors may have had access to or custody of the affected materials.
Discovery and Response Timeline
Adventist HealthCare discovered the loss of the paper documents and films through internal inventory or audit procedures, though the exact discovery date and mechanism were not detailed in the breach submission. Upon discovery, the organization initiated an investigation to determine the scope of the loss, identify which individuals were affected, and assess what specific health information may have been compromised. The entity subsequently notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The involvement of a business associate in this breach suggests that Adventist HealthCare coordinated with third-party entities during both the investigation and notification process, as business associates are jointly responsible for HIPAA compliance and breach notification obligations.
Breach Mechanism and Operational Context
The loss of paper documents and films represents a physical security breach rather than a technological one. Paper-based medical records and radiographic films (X-rays, CT scans, MRI images) remain common in healthcare settings despite the industry's shift toward electronic health records (EHRs). These physical materials are particularly vulnerable to loss through several mechanisms: misplacement during file transfers, loss during transport between facilities, theft from unsecured storage areas, or disposal errors. The involvement of a business associate suggests the materials may have been in transit to or from an external vendor—potentially a medical records storage company, imaging center, transcription service, or document destruction vendor. Physical security failures of this nature often occur at transition points in the document lifecycle, such as during courier delivery, temporary storage, or handoff between departments or organizations. The fact that this breach involved films (radiographic images) in addition to paper documents indicates that the lost materials likely contained comprehensive clinical information spanning multiple service lines.
Organizational Context
Adventist HealthCare is a regional healthcare system based in Maryland with multiple facilities and service lines. The organization operates hospitals, clinics, and ancillary services across the state, serving a diverse patient population. As a faith-based healthcare system affiliated with the Seventh-day Adventist Church, Adventist HealthCare operates under standard HIPAA compliance frameworks while maintaining its organizational mission. The system's size and multi-facility structure create inherent complexity in managing physical records across multiple locations, increasing the risk of loss or misplacement. The involvement of business associates in this breach reflects the reality that modern healthcare organizations frequently outsource records management, storage, transportation, and destruction services to specialized vendors. This distributed model, while operationally efficient, creates additional security touchpoints where breaches can occur.
Patient Impact and Affected Population
Approximately 1,300 individuals were affected by this breach, representing patients who had received care at Adventist HealthCare facilities and whose records were among the lost documents and films. These individuals likely received notification letters detailing the breach, the types of information potentially exposed, and recommended protective measures. The affected population may span multiple service lines and facilities within the Adventist HealthCare system, suggesting the loss was not isolated to a single department or location. Patients affected by loss of paper records and films face different risks than those affected by cyber breaches, as the information is no longer in the organization's control and may be permanently lost, destroyed, or potentially accessed by unauthorized individuals who may have found the materials. The notification timeline would have commenced from the discovery date, with Adventist HealthCare required to provide written notice to all affected individuals within 60 days.
Protected Health Information Exposed
The lost paper documents and films likely contained multiple categories of sensitive health information. Medical records typically include patient names, dates of birth, medical record numbers, addresses, phone numbers, insurance information, diagnoses, treatment histories, medication lists, laboratory results, and clinical notes. Radiographic films (X-rays, CT scans, MRI images) contain identifying information linked to specific imaging studies and clinical findings. Depending on the nature of the records lost, the materials may have included psychiatric records, substance abuse treatment information, HIV status, or other highly sensitive diagnoses. Insurance information and financial data may also have been present on billing-related documents. The combination of demographic information, clinical data, and imaging studies creates a comprehensive profile of patient health status that could be misused if accessed by unauthorized parties.
Industry Context and Similar Incidents
Physical loss of paper records and films remains a significant source of HIPAA breaches despite the healthcare industry's transition to electronic systems. According to HHS Office for Civil Rights data, loss of physical documents consistently ranks among the top breach categories affecting healthcare organizations. The HIPAA Breach Notification Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect PHI, including secure storage, controlled access, and proper disposal procedures. Physical security failures often result from inadequate training, insufficient inventory controls, or lapses in vendor management. The involvement of a business associate in this breach underscores the importance of business associate agreements (BAAs) that clearly delineate security responsibilities and breach notification obligations. Healthcare organizations are required to ensure that business associates maintain equivalent security standards and promptly report any breaches or security incidents. Similar incidents involving loss of paper records have affected numerous healthcare providers, highlighting the persistent vulnerability of non-electronic record systems and the need for comprehensive physical security protocols across the entire document lifecycle.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Adventist HealthCare Breach
Monitor credit reports and financial accounts for signs of identity theft or fraudulent activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion)
Review explanation of benefits (EOB) statements from your insurance provider for unauthorized medical services or claims you did not receive
Contact Adventist HealthCare to request confirmation of what specific information was in your lost records and obtain copies of your medical records from the organization's retained systems
Consider enrolling in complimentary credit monitoring or identity theft protection services if offered by Adventist HealthCare as part of their breach response
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies, as lost personal information may be used in phishing or social engineering scams
Request that your medical records be flagged or secured at Adventist HealthCare facilities to prevent unauthorized access or disclosure
Retain copies of breach notification letters and documentation for your records in case you need to dispute fraudulent charges or medical claims in the future
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Maryland Breaches
Search all breaches reported in Maryland
Technical Notes
Adventist HealthCare Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Adventist HealthCare