Adventist HealthCare medium
2025-11-13 | Loss | MD
1,300 individuals affected # Adventist HealthCare Data Breach Report
## Incident Overview
Adventist HealthCare, a healthcare provider operating in Maryland, reported a data breach affecting approximately 1,300 individuals on November 13, 2025. The breach involved the loss of paper documents and films containing protected health information (PHI). This incident represents a physical security failure rather than a cyber-based attack, highlighting the continued vulnerability of traditional paper-based medical record systems in healthcare environments. The loss occurred at an unspecified facility location within the Adventist HealthCare system, and the breach was classified as involving a business associate, suggesting that third-party vendors or contractors may have had access to or custody of the affected materials.
## Discovery and Response Timeline
Adventist HealthCare discovered the loss of the paper documents and films through internal inventory or audit procedures, though the exact discovery date and mechanism were not detailed in the breach submission. Upon discovery, the organization initiated an investigation to determine the scope of the loss, identify which individuals were affected, and assess what specific health information may have been compromised. The entity subsequently notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. The involvement of a business associate in this breach suggests that Adventist HealthCare coordinated with third-party entities during both the investigation and notification process, as business associates are jointly responsible for HIPAA compliance and breach notification obligations.
## Breach Mechanism and Operational Context
The loss of paper documents and films represents a physical security breach rather than a technological one. Paper-based medical records and radiographic films (X-rays, CT scans, MRI images) remain common in healthcare settings despite the industry's shift toward electronic health records (EHRs). These physical materials are particularly vulnerable to loss through several mechanisms: misplacement during file transfers, loss during transport between facilities, theft from unsecured storage areas, or disposal errors. The involvement of a business associate suggests the materials may have been in transit to or from an external vendor—potentially a medical records storage company, imaging center, transcription service, or document destruction vendor. Physical security failures of this nature often occur at transition points in the document lifecycle, such as during courier delivery, temporary storage, or handoff between departments or organizations. The fact that this breach involved films (radiographic images) in addition to paper documents indicates that the lost materials likely contained comprehensive clinical information spanning multiple service lines.
## Organizational Context
Adventist HealthCare is a regional healthcare system based in Maryland with multiple facilities and service lines. The organization operates hospitals, clinics, and ancillary services across the state, serving a diverse patient population. As a faith-based healthcare system affiliated with the Seventh-day Adventist Church, Adventist HealthCare operates under standard HIPAA compliance frameworks while maintaining its organizational mission. The system's size and multi-facility structure create inherent complexity in managing physical records across multiple locations, increasing the risk of loss or misplacement. The involvement of business associates in this breach reflects the reality that modern healthcare organizations frequently outsource records management, storage, transportation, and destruction services to specialized vendors. This distributed model, while operationally efficient, creates additional security touchpoints where breaches can occur.
## Patient Impact and Affected Population
Approximately 1,300 individuals were affected by this breach, representing patients who had received care at Adventist HealthCare facilities and whose records were among the lost documents and films. These individuals likely received notification letters detailing the breach, the types of information potentially exposed, and recommended protective measures. The affected population may span multiple service lines and facilities within the Adventist HealthCare system, suggesting the loss was not isolated to a single department or location. Patients affected by loss of paper records and films face different risks than those affected by cyber breaches, as the information is no longer in the organization's control and may be permanently lost, destroyed, or potentially accessed by unauthorized individuals who may have found the materials. The notification timeline would have commenced from the discovery date, with Adventist HealthCare required to provide written notice to all affected individuals within 60 days.
## Protected Health Information Exposed
The lost paper documents and films likely contained multiple categories of sensitive health information. Medical records typically include patient names, dates of birth, medical record numbers, addresses, phone numbers, insurance information, diagnoses, treatment histories, medication lists, laboratory results, and clinical notes. Radiographic films (X-rays, CT scans, MRI images) contain identifying information linked to specific imaging studies and clinical findings. Depending on the nature of the records lost, the materials may have included psychiatric records, substance abuse treatment information, HIV status, or other highly sensitive diagnoses. Insurance information and financial data may also have been present on billing-related documents. The combination of demographic information, clinical data, and imaging studies creates a comprehensive profile of patient health status that could be misused if accessed by unauthorized parties.
## Industry Context and Similar Incidents
Physical loss of paper records and films remains a significant source of HIPAA breaches despite the healthcare industry's transition to electronic systems. According to HHS Office for Civil Rights data, loss of physical documents consistently ranks among the top breach categories affecting healthcare organizations. The HIPAA Breach Notification Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect PHI, including secure storage, controlled access, and proper disposal procedures. Physical security failures often result from inadequate training, insufficient inventory controls, or lapses in vendor management. The involvement of a business associate in this breach underscores the importance of business associate agreements (BAAs) that clearly delineate security responsibilities and breach notification obligations. Healthcare organizations are required to ensure that business associates maintain equivalent security standards and promptly report any breaches or security incidents. Similar incidents involving loss of paper records have affected numerous healthcare providers, highlighting the persistent vulnerability of non-electronic record systems and the need for comprehensive physical security protocols across the entire document lifecycle.