The Harris Center for Mental Health and IDD

Your Personal Info Could Be

Exposed Online After

This Hospital Breach

Breach Description

The Harris Center for Mental Health and IDD, a significant mental health service provider based in Texas, experienced a data breach on November 7, 2023. This incident led to unauthorized access to the organization’s network, affecting the personal and medical information of 238,463 individuals. The compromised data included a wide range of sensitive information such as names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, U.S. Alien Registration numbers, driver’s license/state ID numbers, financial account information, medical information, and health insurance information[1][2][16][18].

In response to the breach, The Harris Center took immediate action by shutting down its network to prevent further unauthorized access and mitigate the impact. They initiated an investigation with the assistance of third-party cybersecurity experts to understand the extent of the breach and identify the compromised data[1][4][14]. The Harris Center also reported the incident to law enforcement and began working with the Harris County Office of Homeland Security & Emergency Management and the Harris County Information Technology department to manage the situation[10][14].

To address the potential risks to affected individuals, The Harris Center has offered credit monitoring and identity protection services. They have also encouraged individuals to remain vigilant by monitoring their credit reports and account statements for any suspicious activity[1][9]. The Harris Center has reviewed and is updating its policies and procedures to enhance data security and prevent future incidents[1][2].

This breach is part of a larger trend of cyberattacks targeting healthcare providers, with The Harris Center itself having experienced a previous significant attack earlier in the year, which involved the MOVEit Transfer solution and affected 599,367 individuals[5][15]. The healthcare sector continues to be a prime target for cybercriminals due to the sensitive nature of the data held by these organizations, underscoring the critical need for robust cybersecurity measures and protocols.

The Harris Center for Mental Health and IDD is a key provider of behavioral health and IDD services in Harris County, Texas, operating across 86 locations and serving approximately 80,000 individuals annually[18].

Citations:

  1. https://www.theharriscenter.org/notice-data-security-incident
  2. https://healthitsecurity.com/news/healthcare-data-breaches-continue-to-impact-patients-in-new-year
  3. https://www.theharriscenter.org
  4. https://abc13.com/the-harris-center-for-mental-health-cyber-attack-patient-delays-employee-files-inaccessible/14049544/
  5. https://healthitsecurity.com/news/third-party-data-breaches-continue-to-dominate-breach-notifications
  6. https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
  7. https://www.theharriscenter.org/harris-center-mental-health-and-idd-notice-privacy-practices
  8. https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf?ref=blog.gitguardian.com
  9. https://www.theleadernews.com/community/the-harris-center-for-mental-health-and-idd-issues-november-data-breach-alert/article_51bd74d6-ae39-11ee-bfab-fb744576baf5.html
  10. https://www.houstonpublicmedia.org/articles/news/health-science/2023/11/09/469042/harris-county-mental-health-provider-targeted-in-suspected-ransomware-attack/
  11. https://www.theharriscenter.org/sites/default/files/2023-10/Full%20Board%20Meeting%20Packet%20October%202023.pdf
  12. https://www.chron.com/news/houston-texas/article/cyberattack-houston-harris-county-texas-18330891.php
  13. https://www.idstrong.com/sentinel/national-behavioral-health-clinic-suffers-ransomware/
  14. https://www.khou.com/article/news/local/harris-center-cyber-attack/285-3c5e3f4b-6f2a-49cc-ab85-01288ba89745
  15. https://www.hipaa.info/cyberattack-on-financial-asset-management-systems-the-harris-center-for-mental-health-munsen-healthcare-and-st-bernards-healthcare/
  16. https://www.hipaajournal.com/ransomware-harris-center-mental-health-fams/
  17. https://www.houstonpublicmedia.org/articles/news/2023/07/12/456762/millions-of-hca-healthcare-patients-including-those-in-houston-had-personal-info-stolen/
  18. https://www.jdsupra.com/legalnews/the-harris-center-for-mental-health-and-3528818/
Breach Submission Date Aug 17, 2023
Converted Entity Name The Harris Center for Mental Health and IDD
Converted Entity Type Healthcare Provider
State TX
Individuals Affected 599,367
Breach Type Hacking/IT Incident

Breach Information Location Network Server, Other

Business Associate Present Yes