Skip to content

Allina Health

Disclosed Apr 6, 201511 years ago6,195 affectedConfirmed

Official notice

On October 27, 2015, the covered entity (CE), Alina Health, discovered that its janitorial vendor erroneously placed its patients’ protected health information (PHI) in the trash dumpster. The breach affected 6,195 individuals and the types of PHI involved included financial, demographic, and clinical information. The CE provided notification of the breach to HHS, affected individuals, and the media and also posted substitute notice on its website. Following the breach, the CE investigated the breach, updated its physical safeguards policy, and educated its workforce on its updated policy. OCR obtained a copy of the CE’s business associate agreement with Iron Mountain for PHI disposal services. OCR obtained documented assurances that the CE implemented the corrective actions taken in response to this breach incident.

What is known

People affected6,195 (as reported to HHS)
DisclosedApr 6, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Allina Health (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 6, 2015838
HHS archivetotalDec 23, 20156,195

Other breaches at Allina Health

BreachAffected
Disclosed Apr 28, 2023Apr 28, 20233 years agoInsider1,042
Disclosed Sep 11, 2020Sep 11, 20206 years agoHacking199K
Disclosed Nov 4, 2013Nov 4, 201312 years agoInsider3,807
History of this record
  • 2026-09-25 · disclosed: 2015-12-23 to 2015-04-06 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Allina Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.