Help at Home Data Breach
Help at Home Improper Disposal of Patient Records
What happened in the Help at Home data breach?
The Help at Home data breach was reported on June 17, 2022 and affected 800 individuals. The breach type was Improper Disposal involving Paper/Films. This breach occurred in Illinois. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Help at Home Breach Details
Help at Home Data Breach Report
Incident Overview
Help at Home, a healthcare organization operating in Illinois, experienced a data breach involving the improper disposal of patient records on June 17, 2022. The breach was classified as an "improper disposal" incident, meaning that protected health information (PHI) contained on paper documents and films was not securely destroyed according to HIPAA standards. Instead of being shredded, incinerated, or otherwise rendered unreadable, these physical records were disposed of in a manner that allowed unauthorized individuals to potentially access sensitive patient information. This type of breach represents a significant departure from required data handling protocols and indicates a failure in the organization's document lifecycle management procedures.
Discovery and Response Timeline
The breach was discovered and reported to the Department of Health and Human Services (HHS) on June 17, 2022, though the exact date of discovery relative to the actual improper disposal is not specified in the available records. Upon discovery, Help at Home initiated an investigation to determine the scope of the breach, identify which patient records were improperly disposed of, and assess what information may have been exposed. The organization was required under HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) to notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. The submission date indicates the organization met its obligation to report the incident to HHS within the required timeframe.
Breach Mechanism and Operational Details
Improper disposal breaches involving paper and film records typically occur when healthcare organizations fail to implement adequate document destruction protocols. In this case, patient records—which may have included intake forms, medical histories, treatment notes, billing information, and other documentation—were not securely destroyed. Instead, they were likely placed in regular waste streams, donated to recycling facilities without proper sanitization, or otherwise made accessible to unauthorized parties. Paper-based breaches of this nature are particularly concerning because physical documents cannot be remotely monitored or recalled once they leave the organization's control. The breach location designation of "Paper/Films" indicates that the compromised records were in physical format rather than electronic, which typically suggests older records, archived materials, or organizations that maintain hybrid paper-electronic systems. The absence of a business associate involvement suggests that Help at Home was directly responsible for the disposal process rather than contracting with a third-party document destruction vendor.
Organizational Context
Help at Home operates as a healthcare service provider in Illinois, likely providing home-based care services such as nursing, therapy, personal assistance, or medical equipment provision. The organization's name and service model suggest it delivers care to patients in their residences rather than in a centralized facility. With 800 individuals affected by this breach, Help at Home appears to be a mid-sized regional provider rather than a large health system. The organization's operations span the state of Illinois, serving a community-based patient population. The fact that this breach involved improper disposal of physical records suggests the organization may have been conducting records management activities, such as purging outdated files or transitioning to electronic systems, without implementing adequate safeguards during the transition process.
Patient Impact and Notification
Approximately 800 individuals were affected by this breach, meaning their protected health information was potentially exposed through the improper disposal of paper and film records. These patients likely received breach notification letters from Help at Home detailing what information may have been compromised and what steps they should take to protect themselves. The notification would have been required to include: a description of the breach; the types of information involved; steps patients should take to protect themselves; what Help at Home is doing to investigate and prevent future breaches; and contact information for questions. Given the June 17, 2022 submission date, affected individuals should have received notifications by mid-August 2022 at the latest, in compliance with the 60-day notification requirement.
HIPAA Compliance and Industry Context
Under HIPAA's Security Rule (45 CFR §§ 164.300-318), covered entities must implement administrative, physical, and technical safeguards to protect patient information. The disposal of PHI is specifically addressed in the Security Rule's requirement for secure disposal procedures. The Privacy Rule (45 CFR §§ 164.500-534) further requires that covered entities implement policies and procedures to ensure that PHI is not improperly disclosed. Improper disposal breaches represent a failure in the physical safeguards component of HIPAA compliance, specifically the lack of adequate disposal procedures. According to HHS data, improper disposal incidents account for a significant portion of healthcare data breaches, particularly among smaller healthcare organizations and those with legacy paper-based record systems. These breaches are often preventable through implementation of standardized document destruction protocols, staff training on proper disposal procedures, and regular audits of records management practices. The 800-person impact in this case is consistent with mid-sized healthcare organizations that may lack the sophisticated records management infrastructure of larger health systems.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Help at Home Breach
Monitor credit reports and financial accounts closely for signs of unauthorized activity; consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent fraudulent account opening
Review medical records and explanation of benefits statements from your healthcare providers to identify any unauthorized medical services or claims; contact providers immediately if you identify suspicious activity
Change passwords for any online healthcare portals or accounts associated with Help at Home or related healthcare providers, using strong, unique passwords that are not reused across other accounts
Consider enrolling in identity theft protection or credit monitoring services, particularly those that include medical identity theft monitoring, and maintain vigilance for any suspicious communications claiming to be from healthcare providers or insurers
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Illinois Breaches
Search all breaches reported in Illinois