---
title: Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach
description: Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach
image: https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-906812954-1.jpg
---

[Skip to the main content.](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#main-content)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

[![OTT powerd by VN big](https://ontimetech.valeonetworks.com/hs-fs/hubfs/OTT%20powerd%20by%20VN%20big.png?width=500&height=175&name=OTT%20powerd%20by%20VN%20big.png "OTT powerd by VN big")](https://ontimetech.valeonetworks.com)

- [Services](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

Toggle Menu

Toggle Menu

[415-294-5250](tel:4152945250) [Client Portal](https://portal.Valeonetworks.com)

- [Services *Toggle Menu*](https://ontimetech.valeonetworks.com/our-services/) 
    - [Managed It Services](https://ontimetech.valeonetworks.com/our-services/managed-it/)
    - [Cybersecurity](https://ontimetech.valeonetworks.com/our-services/cybersecurity/)
    - [Cloud Solutions](https://ontimetech.valeonetworks.com/our-services/cloud-solutions/)
    - [Compliance](https://ontimetech.valeonetworks.com/our-services/compliance/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources *Toggle Menu*](https://ontimetech.valeonetworks.com/resources/) 
    - [Blog](https://ontimetech.valeonetworks.com/blog)
- [About *Toggle Menu*](https://ontimetech.valeonetworks.com/about/) 
    - [Client Testimonials](https://ontimetech.valeonetworks.com/testimonials/)

- Example Link
- Example Link
- Example Link

[*Facebook*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0) [*Instagram*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0) [*LinkedIn*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0) [*Twitter*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0) [*Youtube*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0) [*Medium*](https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach#0)

 4 min read

# Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/lance-stone) :  Feb 7, 2019, 10:59:00 AM

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services)

![Email Breach](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-906812954-1.jpg)

When people go to their doctors, they assume their information is protected. They freely and willingly provide personal information, like social security numbers. Their primary concern is their health and so they literally trust their lives in the hands of medical professionals and providers. This assumption that patient data is protected may be derived from the assumption that medical facilities are all aligned and in [compliance](https://www.ontimetech.com/compliance/) with Health Insurance Portability and Accountability (HIPAA). Everyone signs the HIPAA forms and so everyone assumes — even without thinking it — that they are protected and that the medical facility and/or medical providers are in compliance. Indeed, medical providers may believe they are in compliance and their patient data is protected until it happens: the data breach. Instantly, hundreds and thousands and even millions of patients’ information is compromised. Not to mention: the medical entity where the breach occurred may be held liable for it.

## Breach of Patient Data Already Making Waves in 2019: The Example of Valley Hope Association

Just recently, a data breach was investigated and confirmed at Valley Hope Association. It’s a Kansas-based nonprofit organization that treats patients with drug and alcohol addictions. They have 16 facilities located in seven states:

1. Arizona
2. Colorado
3. Kansas
4. Missouri
5. Nebraska
6. Oklahoma
7. Texas.

Patients number in the thousands across these seven states. As of the last week of January 2019, the organization has been notifying these patients — former and current — that there was a data breach and their information may have been accessed.

It all started in October 2018. An employee’s email account had suspicious activity. The investigation commenced with this employee’s email account. On November 23, 2018, it was confirmed: a cybercriminal hacked into the employee’s email account, and from there, was able to access patient information. The information compromised includes:

- Social security numbers
- Dates of birth
- Financial account information
- Patient claim or billing information
- Driver’s license or state identification card numbers
- Health insurance
- Medical records
- Medications, and
- More.

These kinds of breaches are the beginning of identity theft. When it happens in medical facilities, it is all the more stressful because these are patients dealing with health issues. Identity theft is not a matter they want to deal with on top of their health issues. Following the breach, Valley Hope has taken two steps:

1. It has provided its patients with free credit monitoring and identity protection services; and
2. It has added additional security measures designed to secure patient data.

Unfortunately, the Valley Hope Association’s breach of patient data is not an isolated event. Many other medical facilities across the country have experienced data breaches. Examples of patient data breaches that occurred in 2018 include:

- [Catawba Valley](https://www.healthcareitnews.com/news/3-phishing-hacks-breach-20000-catawba-valley-patient-records) patient records were breached by three phishing hacks.
- [Centers for Medicare & Medicaid Services (CMS)](https://www.healthcarefinancenews.com/news/cms-responds-data-breach-affecting-75000-federal-aca-portal) confirmed 75,000 people were affected by a data breach in the ACA portal.
- [Minnesota Department of Human Services](https://www.healthcareitnews.com/news/two-phishing-attacks-minnesota-dhs-breach-21000-patient-records) was the victim of two phishing attacks affecting 21,000 patient records.
- [Fetal Diagnostic Institute in Hawaii ](https://www.healthcareitnews.com/news/ransomware-attack-fetal-diagnostic-lab-breaches-40800-patient-records)was the victim of ransomware attacks resulting in data breaches of 40,800 patient records.
- [Legacy Health, an Oregon-based health system](https://www.healthcareitnews.com/news/phishing-attack-breaches-38000-patient-records-legacy-health), experienced phishing attacks that led to 38,000 patient record breaches.
- [Augusta University Health](https://www.healthcareitnews.com/news/417000-augusta-university-health-patient-records-breached-nearly-one-year-ago) confirmed in 2018 that 417,000 patient records had been breached.
- [UnityPoint Health](https://www.healthcareitnews.com/news/14-million-patient-records-breached-unitypoint-health-phishing-attack) experienced two large data breaches in 2018, exposing 1.4 million patient accounts to hackers.
- [LabCorp](https://www.healthcareitnews.com/news/labcorp-goes-down-after-network-breach-putting-millions-patient-records-risk) confirmed millions of records have been compromised and are at risk due to the hacking that forced a network shutdown.
- A [Missouri-based Blue Spring Family Care](https://www.healthcareitnews.com/news/ransomware-malware-attack-breaches-45000-patient-records) facility was the victim of ransomware malware, which put 45,000 patient records at risk.
- [Banner Health](https://www.healthcareitnews.com/news/ocr-investigating-banner-health-2016-breach-37-million-patient-records) breach in Arizona compromised around 3.7 million patient records.

These are just a few of the many security breaches of patient data that occurred in 2018. As can be understood from these examples, healthcare is a lucrative target for hackers, and as technology advances, so do the hackers’ capabilities. That’s why it is imperative that medical facilities, providers, and professionals take steps to ensure their outsourced IT services providers offer all the latest technology to secure patient information.

## What does HIPAA say about patient data protection, responsibility, and consequences?

The HIPAA Privacy Rule sets out to protect “individually identifiable health information” in the possession of a covered entity or its business association regardless if this health information is in electronic or paper form or transmitted orally. [Covered entities](https://privacyruleandresearch.nih.gov/pr_06.asp) include:

- Health plans
- Health care clearinghouses
- Health care providers “who electronically transmit any health information in connection with transactions for which the \[U.S. Department of Health and Human Services (HHS)\] has adopted standards.”

The individually identifiable health information is known as protected health information or PHI. According to [HHS](https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html#protected), PHI includes demographic information relating to:

- “an individual’s past, present, or future physical or mental health or condition
- the provision of health care to the individual, or
- the past, present, or future payment for the provision of health care to the individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual. Protected health information includes many common identifiers (e.g., name, address, birth date, Social Security Number) when they can be associated with the health information listed above.”

Covered entities must take measures to protect PHI. Traditionally, a covered entity breached HIPAA regulations when PHI was accessed by an unauthorized person due to unsecured PHI. When this happens, the covered entity is responsible for a breach in HIPAA regulations. But this responsibility is not as straightforward when the breach is made by ransomware or other malware activity. If the covered entity is found to be in violation of HIPAA due to these data breaches, then [heavy financial fines may be imposed along with other required corrective action](https://healthitsecurity.com/news/lessons-learned-from-the-2015-ocr-hipaa-settlements). Depending on the size of the entity and the amount of the fine and other imposed penalties, a data breach could be detrimental not only to the patients whose information was compromised but to the survival and existence of the facility, provider, or professional.

## What can medical facilities do to safeguard their patient data?

Medical facilities or any covered entity and their business associates have options when safeguarding their patient data. These options should be interpreted into a plan of action.

- First and foremost, these facilities must comply with HIPAA regulations.
- Second, they must comply with HIPAA regulations by ensuring they are using the most advanced technologies to safeguard patient data. New technologies develop on a regular basis. You should hire an IT team or outsource your IT needs to an IT services provider who regularly keeps up to date with advancements in technology and consistently implements the technology into their services. If you hire such a team, you can rest assured that data is being protected to the best of technologies’ capabilities.
- Third, covered entities and their business associates must thoroughly vet their IT Team and/or third-party IT services provider. There have been cases in 2018 where breaches were made by tech vendors and other third-party IT services providers, e.g., the case of [MedCall Advisors in North Carolina](https://www.healthcareitnews.com/news/update-misconfigured-database-breaches-thousands-medcall-advisors-patient-files).
- Fourth, policies and procedures should be in place to ensure that on an ongoing basis, best practices are honored to safeguard PHI. These policies and procedures should apply to all staff, employees, medical professionals, and the IT team — even if IT services are outsourced.

Ultimately the responsibility comes down to the party in possession of the patient data and covered by HIPAA regulations. Don’t let what happened to Valley Hope Association happen to you. Start the new year off right: make sure your PHI is secure and safe.

- [Tweet](https://twitter.com/share)

#### ![BusinessOwnerGuidetoM&A-1](https://ontimetech.valeonetworks.com/hs-fs/hubfs/BusinessOwnerGuidetoM%26A-1.png?width=303&height=209&name=BusinessOwnerGuidetoM%26A-1.png)

#### Download our eBook*THE ULTIMATE ROADMAP TO CMMC COMPLIANCE* by filling out the form below!

#### [Microsoft Support for Non-Profit Organizations in San Francisco](https://ontimetech.valeonetworks.com/blog/microsoft-support-non-profits)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Jul 14, 2019, 10:52:01 AM

Microsoft Support for Non-Profit Organizations in San Francisco Everything non-profit’s need to know about managing and optimizing Microsoft solutions

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/microsoft-support-non-profits)

[![Anthem Security Breach Case Will Change How Organizations Work with Regulators](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-496093390-1.jpg)](https://ontimetech.valeonetworks.com/blog/anthem-security-breach-case-will-change-how-organizations-work-with-regulators)

#### [Anthem Security Breach Case Will Change How Organizations Work with Regulators](https://ontimetech.valeonetworks.com/blog/anthem-security-breach-case-will-change-how-organizations-work-with-regulators)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Dec 16, 2016, 11:55:48 AM

A federal class action lawsuit filed by at least 100 victims of a data breach involving Anthem Blue Cross of California may have consequences that...

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/anthem-security-breach-case-will-change-how-organizations-work-with-regulators)

[![Protecting Your Organization For IoT Exploits (Research/Information)](https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/ThinkstockPhotos-851986796.jpg)](https://ontimetech.valeonetworks.com/blog/protecting-your-organization-for-iot-exploits-research-information)

#### [Protecting Your Organization For IoT Exploits (Research/Information)](https://ontimetech.valeonetworks.com/blog/protecting-your-organization-for-iot-exploits-research-information)

[Lance Stone](https://ontimetech.valeonetworks.com/blog/author/ulisticadmin) : Jul 6, 2018, 11:46:17 AM

Is Your Organization Protected Against These IoT Exploit Risks? In a changing digital environment, is your business keeping up with risk management?

[Managed IT Services](https://ontimetech.valeonetworks.com/blog/tag/managed-it-services) 

[Read More](https://ontimetech.valeonetworks.com/blog/protecting-your-organization-for-iot-exploits-research-information)

![OTT White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/OTT%20Logo/OTT%20White%20logo.png?width=524&height=140&name=OTT%20White%20logo.png)

 

##### About

About

On Time Tech is an IT Support and Computer Services company serving California. We provide services to the areas in and around We know businesses like yours need technology support in order to run highly-effective organizations. Leverage pro-growth technology services for your company now.

##### Explore On Time Time

Explore On Time Time

- [Our Services](https://ontimetech.valeonetworks.com/our-services/)
- [Industries](https://ontimetech.valeonetworks.com/industries/)
- [Resources](https://ontimetech.valeonetworks.com/resources/)
- [About](https://ontimetech.valeonetworks.com/about/)
- [Contact](https://ontimetech.valeonetworks.com/contact/)

##### Contact

Contact

**San Francisco:**  
1717 Fifth Ave  
San Rafael, CA 94901

[415-294-5250](tel:4152945250)

Business Hours:   
M-F: 8AM-9PM

- [Privacy Policy](https://ontimetech.valeonetworks.com/privacy-policy/)

© 2026 On Time Tech

[*Facebook*](https://www.facebook.com/ontimetechsf/)[*Twitter*](https://twitter.com/on_time_tech?lang=en)[*LinkedIn*](https://www.linkedin.com/company/ontimetech/)[*YouTube*](https://www.youtube.com/channel/UCubqs9PU_WWF-RFhfK9xNpw)

[![Alura White logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/VN%20-%20Division%20Logos/Alura%20White%20logo.png?width=295&height=115&name=Alura%20White%20logo.png)](https://alura.valeonetworks.com/) [![Next.I.T._White-Logo](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Next.I.T._White-Logo.png?width=328&height=136&name=Next.I.T._White-Logo.png)](https://next-it.net/) [![White-OTT-Logo-1-768x253](https://ontimetech.valeonetworks.com/hs-fs/hubfs/White-OTT-Logo-1-768x253.png?width=313&height=103&name=White-OTT-Logo-1-768x253.png)](https://www.ontimetech.com/) [![Valeo-Logo-White (1)](https://ontimetech.valeonetworks.com/hs-fs/hubfs/Valeo-Logo-White%20(1).png?width=288&height=123&name=Valeo-Logo-White%20(1).png)](https://valeonetworks.com/)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Lance Stone",
    "url" : "https://ontimetech.valeonetworks.com/blog/author/lance-stone"
  },
  "dateModified" : "2024-01-10T16:39:45.610Z",
  "datePublished" : "2019-02-07T15:59:00.000Z",
  "headline" : "Kansas Addiction Treatment Organization’s Email Hack Leads To Data Breach",
  "image" : [ "https://ontimetech.valeonetworks.com/hubfs/Blog%20Images/Imported_Blog_Media/GettyImages-906812954-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://ontimetech.valeonetworks.com/blog/kansas-addiction-treatment-organizations-email-hack-leads-to-data-breach",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://ontimetech.valeonetworks.com/hubfs/OTT%20-%20Color%20Logo.png"
    },
    "name" : "Valeo Networks"
  }
}
```