Option Care Health, a provider of home and alternate site infusion therapy, recently reported a data security incident that compromised the protected health information (PHI) of 2,897 individuals.
Option Care Health (OCH) discovered a data breach on November 15, 2024, caused by unauthorized access to an employee’s email account. The breach was traced back to July 31, 2024, when an unauthorized party accessed the account, potentially exposing sensitive consumer data, including PHI. OCH conducted a thorough investigation and confirmed that the unauthorized party had access to certain individuals’ PHI.
While the full scope of the breach is still under investigation, the fraudulent activities reported include:
These tactics aim to deceive recipients into sharing sensitive personal information or accessing malicious websites.
Related: Tips to spot phishing emails disguised as healthcare communication
Option Care Health has alerted its patients, partners, and customers about these scams. The organization encourages individuals to stay vigilant and has established a dedicated fraud reporting email and phone line for those who suspect fraudulent activity:
Phishing attacks are the most common cause, where attackers trick employees into sharing login credentials or clicking malicious links, granting unauthorized access to email accounts.
Yes, if PHI is exposed through compromised internal emails, it still constitutes a HIPAA violation, as unauthorized access to protected information breaches privacy regulations.
An incident response plan should include steps for isolating affected accounts, notifying impacted individuals, conducting a root cause analysis, and reporting to regulatory authorities if required.