Ascension Borgess Hospital
Disclosed Nov 14, 20196 years ago996 affectedConfirmed
Ascension Borgess Hospital, the covered entity (CE), reported that an employee emailed 996 individuals without using the blind copy function. The protected health information (PHI) was limited to email addresses only. The CE notified HHS, affected individuals, and the media. The CE retrained the responsible employee on the importance of patient privacy and provided HIPAA Privacy Rule training to all staff members. OCR obtained documentation that the CE implemented the corrective actions noted.
What is known
| People affected | 996 (as reported to HHS) |
|---|---|
| Disclosed | Nov 14, 2019 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Ascension Borgess Hospital (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 14, 2019 | 996 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.