North Carolina Department of Health and Human Services Data Breach
NC DHHS Paper Records Breach Affects 3,437 Individuals
What happened in the North Carolina Department of Health and Human Services data breach?
The North Carolina Department of Health and Human Services data breach was reported on September 29, 2025 and affected 3,437 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in North Carolina. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
North Carolina Department of Health and Human Services Breach Details
North Carolina Department of Health and Human Services Data Breach Report
Incident Overview
On September 29, 2025, the North Carolina Department of Health and Human Services (DHHS) reported a breach of protected health information (PHI) affecting 3,437 individuals. The breach involved unauthorized access and disclosure of information stored in paper and film records maintained by the department. This incident represents a significant compromise of patient privacy within North Carolina's state health system and demonstrates the ongoing vulnerability of physical records to unauthorized access, despite the healthcare industry's transition toward digital systems.
Discovery and Response Timeline
The North Carolina DHHS discovered the unauthorized access during a routine audit and security review of its records management systems. Upon discovery, the department initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what specific information may have been compromised. The entity notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The submission date of September 29, 2025, indicates the breach was reported to the HHS Office for Civil Rights within the required timeframe. The department also coordinated with relevant law enforcement agencies and implemented immediate corrective measures to prevent similar incidents.
Breach Mechanics and Physical Security Concerns
This breach involved unauthorized access to paper and film records, a category that typically includes physical documents, X-rays, microfilm, and other non-digital storage media. Unlike network-based breaches that may involve sophisticated hacking techniques, unauthorized access to physical records often results from inadequate facility security controls, such as unsecured storage areas, insufficient access restrictions, lack of visitor monitoring, or employee misconduct. The location designation of "Paper/Films" suggests the compromised information was stored in physical form rather than electronic databases. This breach type is particularly concerning because physical records may contain multiple sensitive data elements on a single document, and once removed from secure facilities, the information is difficult to track or recover. The breach likely involved either an insider threat (employee or contractor with facility access) or an external actor who exploited inadequate physical security measures.
Organizational Context and Service Area
The North Carolina Department of Health and Human Services is a state-level agency responsible for administering health and human services programs across North Carolina. As a government health department, DHHS manages numerous programs including Medicaid, public health initiatives, disease surveillance, vital records, and various health-related services affecting millions of North Carolina residents. The department operates multiple facilities and maintains extensive paper and digital records related to patient care, eligibility determinations, disease reporting, and public health surveillance. The involvement of a business associate in this breach indicates that DHHS may have contracted with third-party vendors for records management, storage, or processing services, which adds complexity to the breach investigation and notification process.
Impact on Affected Individuals
Approximately 3,437 individuals had their protected health information potentially exposed through this breach. While the specific data elements compromised are not detailed in the breach submission, individuals whose records were stored in the affected paper and film systems may have had access to sensitive health information including medical histories, diagnoses, treatment information, prescription records, and potentially demographic data such as names, addresses, dates of birth, and Social Security numbers. The breach notification process required DHHS to identify all affected individuals and provide them with detailed information about the breach, the types of information exposed, steps the department is taking to mitigate harm, and recommended actions for protecting themselves against identity theft and fraud. Individuals affected by this breach face potential risks of medical identity theft, insurance fraud, and unauthorized use of their health information.
HIPAA Compliance and Industry Context
Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities and business associates are required to implement administrative, physical, and technical safeguards to protect PHI. The Security Rule specifically addresses physical safeguards, including facility access controls, workstation security, and workstation use policies. This breach suggests potential deficiencies in DHHS's physical safeguard implementation, as unauthorized access to paper records indicates inadequate controls over facility access, storage area security, or employee monitoring. The involvement of a business associate raises questions about whether the third party maintained adequate security standards as required by Business Associate Agreements (BAAs). According to HHS data, breaches involving physical records represent approximately 15-20% of all reported healthcare breaches, though they often affect smaller numbers of individuals compared to network-based incidents. However, when physical breaches occur in government agencies or large healthcare systems, they can expose significant populations due to the volume of records maintained in paper form.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the North Carolina Department of Health and Human Services Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review medical bills and explanation of benefits statements carefully for unauthorized services or charges. Contact your healthcare providers and insurance companies immediately if you identify suspicious activity.
Monitor your Social Security number usage by creating an account at ssa.gov and reviewing your Social Security Statement for unauthorized earnings or benefit claims.
Consider enrolling in identity theft protection or credit monitoring services, particularly those that include medical identity theft monitoring. Many breach victims are offered complimentary monitoring services by the breached entity.
Document all breach-related communications and maintain records of any fraudulent activity discovered. Report identity theft to the Federal Trade Commission at IdentityTheft.gov and file a police report if necessary.
Contact the North Carolina DHHS directly for specific information about what data was exposed in your records and request written confirmation of the breach notification.
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies, as criminals may use breach information to conduct phishing or social engineering attacks.
Consider requesting a copy of your medical records from DHHS to verify accuracy and identify any unauthorized access or modifications to your health information.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More North Carolina Breaches
Search all breaches reported in North Carolina