Charleston Area Medical Center Data Breach Exposes PHI & PII

Published
February 14, 2025
Updated
February 19, 2025
Charleston Area Medical Center Data Breach Exposes PHI & PII
Charleston Area Medical Center
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

On October 2, 2024, Charleston Area Medical Center (CAMC) discovered a data breach resulting from a phishing attack that compromised the email account of one of its users. This breach potentially exposed sensitive information of patients and individuals associated with the healthcare system. The unauthorized access to the email account lasted until October 3, 2024. Fortunately, no other systems or data storage facilities within CAMC were affected by this incident.

The breach affected a small number of individuals, with nine people reported as impacted in Massachusetts. The information that may have been exposed varies per person but could include:

  • First and last name
  • Date of birth
  • Email address
  • Phone number
  • Social Security number
  • Driver’s license
  • Health information
  • Health insurance information

Charleston Area Medical Center's Response

In response to the data breach, CAMC acted swiftly by engaging a respected forensic security provider to investigate the incident. They terminated any unauthorized access to the compromised email account and are implementing additional technical security measures to prevent similar incidents in the future. CAMC routinely trains its employees on data privacy and cybersecurity issues and will conduct further training specifically related to this breach.

For those who might be affected, CAMC advises remaining vigilant by checking medical account statements for any suspicious activity. Although there is currently no evidence of misuse of the exposed information, monitoring for any unusual activity is recommended.

If you have questions or concerns, CAMC has set up a toll-free hotline at 1-877-732-0029, available from 9 AM to 9 PM Eastern Time, Monday through Friday, excluding holidays.

About Charleston Area Medical Center

Charleston Area Medical Center is a nonprofit healthcare system based in Charleston, West Virginia. It operates multiple hospitals, including CAMC General Hospital, CAMC Memorial Hospital, and CAMC Women and Children's Hospital, among others. With nearly 8,000 employees, CAMC serves as a regional referral center and offers a wide range of medical services, including a Level 1 Trauma Center and a comprehensive heart program.

For further details, you can access the full data breach notice on the Massachusetts Attorney General's website and the Vermont Attorney General's website.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • first and last name
  • date of birth
  • e-mail address
  • phone number
  • Social Security number
  • driver’s license
  • health information
  • health insurance information

Join the

Charleston Area Medical Center

data breach lawsuit. It's free to join. 

Join the Lawsuit
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image