Central Iowa Hospital
Disclosed Dec 8, 20178 years ago557 affectedConfirmed
The covered entity (CE), Central Iowa Children’s Hospital – Blank Children’s Hospital (BCH), discovered that patient information was sent to the wrong recipients due to a column misalignment in the corresponding spreadsheet. This breach affected approximately 557 individuals. The protected health information involved in this breach included names, addresses, and zip codes. BCH notified all affected individuals, notified HHS, and provided substitute notice. As a result of the breach, BCH updated its privacy training, including mailing procedures. The privacy officer conducted an internal investigation to determine the root cause of the breach. Bases on the investigation, additional safeguards were put in place to protect PHI. Additionally, the employee responsible for the breach was retrained. The CE provided documentation of these corrective steps to OCR.
What is known
| People affected | 557 (as reported to HHS) |
|---|---|
| Disclosed | Dec 8, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Central Iowa Hospital (Healthcare Provider, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 8, 2017 | 557 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.