York Hospital Data Breach
York Hospital: 1,259 Patients Affected by Unauthorized Paper Records Access
What happened in the York Hospital data breach?
The York Hospital data breach was reported on December 23, 2025 and affected 1,259 individuals. The breach type was Unauthorized Access/Disclosure involving Paper/Films. This breach occurred in Maine. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
York Hospital Breach Details
York Hospital Data Breach Report
Incident Overview
York Hospital, located in Maine, experienced an unauthorized access and disclosure incident involving paper-based medical records and films on or around December 23, 2025. The breach resulted in potential exposure of protected health information (PHI) belonging to 1,259 patients. This incident represents a significant breach of patient privacy involving physical documents rather than digital systems, highlighting the continued vulnerability of paper-based medical record storage in healthcare facilities.
Company Response and Investigation
Upon discovery of the unauthorized access to paper records and films, York Hospital initiated an investigation to determine the scope and nature of the breach. The facility notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. The hospital's response included a comprehensive review of access logs, physical security measures, and staff interviews to identify how the unauthorized access occurred and what specific records were compromised. The submission date of December 23, 2025, indicates the hospital reported this incident to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) within the required timeframe.
Specific Details of the Breach
The breach involved unauthorized access to and disclosure of paper medical records and radiographic films stored at the facility. Paper-based breaches typically occur through several vectors: physical theft of documents, unauthorized employee access, inadequate physical security controls, or improper disposal of records. In this case, the location designation of "Paper/Films" indicates the compromised information was stored in physical form rather than electronic systems. This type of breach often results from gaps in physical security infrastructure, such as unlocked storage areas, insufficient access controls, or inadequate monitoring of record rooms. The breach may have involved a single incident of unauthorized access or a series of incidents that went undetected for a period of time before discovery. Unlike digital breaches that may be detected through system logs and network monitoring, paper record breaches often remain undetected longer, potentially affecting a larger volume of records before identification.
Organizational Context
York Hospital is a healthcare facility serving patients in Maine. As a hospital, the organization maintains comprehensive medical records including diagnostic information, treatment histories, and patient demographics. The facility's operations likely include inpatient care, outpatient services, and diagnostic imaging, all of which generate paper records and radiographic films that require secure storage and controlled access. The involvement of 1,259 affected individuals suggests this is a community hospital with a substantial patient population. The fact that no business associate was involved in this breach indicates the unauthorized access occurred within York Hospital's own facilities and staff, rather than through a third-party vendor or contractor.
Patient Impact and Notification
Approximately 1,259 patients had their protected health information potentially exposed through this unauthorized access incident. The compromised information likely includes medical record contents and radiographic imaging, which may contain sensitive clinical information about diagnoses, treatments, medications, and medical history. Affected patients were notified of the breach in accordance with HIPAA requirements. The notification process included information about the nature of the breach, the types of information involved, steps patients should take to protect themselves, and contact information for the hospital's breach response team. Patients were advised to monitor their accounts and credit reports for signs of identity theft or fraud, though the primary risk from this breach relates to medical privacy rather than financial fraud.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities like York Hospital must notify affected individuals, the media (if more than 500 residents of a state are affected), and the HHS Secretary when unsecured PHI is accessed, acquired, used, or disclosed in a manner not permitted by the Privacy Rule. Paper-based breaches represent a significant category of healthcare data incidents, accounting for a substantial portion of reported breaches annually. According to HHS OCR data, breaches involving paper records and physical documents continue to be common, often resulting from inadequate physical security controls, employee negligence, or theft. The 1,259-person impact of this incident falls within the range of typical paper record breaches, which often affect hundreds to thousands of patients depending on the volume of records stored in compromised locations. Healthcare organizations are required to implement administrative, physical, and technical safeguards to protect PHI, including access controls, audit procedures, and secure storage of paper records. This incident underscores the importance of comprehensive physical security measures, staff training on privacy and security protocols, and regular audits of record storage areas to identify and remediate vulnerabilities before unauthorized access occurs.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the York Hospital Breach
Review your medical records and billing statements from York Hospital for any unauthorized services, charges, or treatments you did not receive, and report any discrepancies to the hospital immediately
Monitor your credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for signs of identity theft or fraudulent accounts, and consider placing a fraud alert or credit freeze if suspicious activity is detected
Contact York Hospital's breach response team using the contact information provided in your notification letter to ask specific questions about what information was accessed and obtain additional details about the incident
Be cautious of unsolicited phone calls, emails, or mail claiming to be from healthcare providers or insurance companies requesting personal or medical information, as scammers may use exposed information to impersonate legitimate entities
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Maine Breaches
Search all breaches reported in Maine