Artesia General Hospital Data Breach
Artesia General Hospital Paper Records Breach Affects 1,985 Patients
What happened in the Artesia General Hospital data breach?
The Artesia General Hospital data breach was reported on January 26, 2024 and affected 1,985 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in New Mexico. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Artesia General Hospital Breach Details
Breach Overview
Artesia General Hospital, a healthcare facility located in Artesia, New Mexico, reported a data breach involving unauthorized access to or disclosure of protected health information contained in paper records and films. The breach was submitted to the U.S. Department of Health and Human Services on January 26, 2024, and affected 1,985 individuals. The incident involved physical paper documents and medical films rather than electronic health records, representing a breach of traditional medical record storage systems. The unauthorized access or disclosure may have exposed sensitive patient information typically contained in hospital medical records, including treatment histories, diagnostic information, and personal identifiers.
Company Response
Following the discovery of the unauthorized access or disclosure, Artesia General Hospital initiated an investigation to determine the scope and nature of the breach. The hospital worked to identify which specific paper records and films were involved in the incident and which patients' information may have been compromised. As required under the Health Insurance Portability and Accountability Act (HIPAA), the hospital submitted breach notification to the Department of Health and Human Services within the required timeframe, with the submission occurring on January 26, 2024. The facility likely conducted a thorough review of its physical record security protocols and implemented corrective measures to prevent similar incidents in the future. Affected patients would have been notified in accordance with HIPAA breach notification requirements, which mandate that covered entities notify individuals whose protected health information has been breached within 60 days of discovery.
Specific Details
The breach involved paper documents and films, which indicates that the incident occurred within the hospital's physical record storage areas rather than through electronic systems. Paper and film records typically include original medical charts, radiology films, pathology reports, consent forms, and other documentation that has not been digitized or is maintained in physical form for legal or operational reasons. Unauthorized access to paper records can occur through various means, including improper disposal of documents, theft of physical files, unauthorized viewing by employees or visitors, misfiling that results in disclosure to unauthorized parties, or inadequate physical security controls in record storage areas. The classification as "unauthorized access/disclosure" rather than theft or loss suggests that the records may have been improperly accessed by individuals without proper authorization or inadvertently disclosed to parties who should not have received them. This type of breach often involves internal actors or procedural failures rather than external criminal activity, though the specific circumstances of this incident have not been publicly detailed.
Organizational Context
Artesia General Hospital serves the community of Artesia, New Mexico, a city located in Eddy County in the southeastern part of the state. As a general hospital, the facility provides a range of healthcare services to the local population, including emergency care, inpatient services, surgical procedures, diagnostic imaging, and outpatient treatment. Healthcare facilities in smaller communities like Artesia often serve as critical access points for medical care in rural or semi-rural areas where healthcare resources may be more limited than in larger metropolitan regions. The hospital's patient population likely includes residents of Artesia and surrounding communities who rely on the facility for their healthcare needs. Like many healthcare organizations, Artesia General Hospital maintains both electronic and paper medical records, with paper documents and films still playing a role in medical documentation, particularly for older records or specific types of medical imaging.
Number of People Affected
The breach affected 1,985 individuals whose protected health information was contained in the paper records and films that were subject to unauthorized access or disclosure. These patients likely received care at Artesia General Hospital during a specific timeframe, though the exact period during which the affected records were created has not been publicly specified. The compromised information may have included a wide range of protected health information typically found in hospital medical records, such as patient names, dates of birth, addresses, medical record numbers, dates of service, physician names, diagnoses, treatment information, medication records, laboratory and test results, and potentially insurance information or Social Security numbers if such data was included in the physical files. The specific data elements exposed would depend on the types of records involved and the documentation practices at the facility during the relevant time period.
HIPAA Requirements and Industry Context
Under HIPAA regulations, healthcare providers are required to implement appropriate administrative, physical, and technical safeguards to protect patient information, including paper records. Physical safeguards for paper records typically include locked storage areas, restricted access to file rooms, visitor controls, proper disposal procedures for documents containing protected health information, and employee training on privacy and security requirements. Breaches involving paper records remain a significant concern in the healthcare industry despite the widespread adoption of electronic health records. According to data from the HHS Office for Civil Rights, unauthorized access and disclosure incidents represent a substantial portion of reported breaches, and paper-based breaches continue to occur due to factors such as inadequate physical security, improper disposal practices, and human error. Healthcare organizations must maintain vigilance in protecting both electronic and physical records, as paper documents can be particularly vulnerable to unauthorized viewing, theft, or inadvertent disclosure if proper controls are not consistently maintained.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Artesia General Hospital Breach
Review all Explanation of Benefits (EOB) statements from your health insurance company carefully for any medical services, procedures, or prescriptions that you did not receive. Report any suspicious or unfamiliar charges to your insurance company immediately, as these could indicate medical identity theft.
Contact your healthcare providers to request copies of your medical records and review them for accuracy. Look for any treatments, diagnoses, test results, or other information that does not belong to you, as unauthorized access could have resulted in your records being mixed with another person's information or fraudulent entries being added.
Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus (Equifax, Experian, and TransUnion) if the breach notification indicates that Social Security numbers or other financial identifiers were involved. Monitor your credit reports regularly for unauthorized accounts or inquiries.
Remain vigilant for phishing attempts, suspicious phone calls, or emails that reference your medical information or attempt to obtain additional personal information. Be cautious about unsolicited communications claiming to be from healthcare providers, insurance companies, or government agencies, and verify the legitimacy of any requests for personal information by contacting organizations directly using official contact information.
Keep detailed records of all communications with Artesia General Hospital regarding the breach, including dates, names of representatives you spoke with, and any information provided. Document any time or expenses you incur as a result of the breach, as this information may be relevant if you need to file a complaint or seek remediation.
File a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your rights under HIPAA have been violated or if you are not satisfied with the hospital's response to the breach. You can file complaints online at the HHS OCR website or by mail.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New Mexico Breaches
Search all breaches reported in New Mexico