City of Detroit
Disclosed Feb 5, 20188 years ago544 affectedConfirmed
The covered entity (CE), City of Detroit, reported that an unencrypted flash drive containing protected health information (PHI) had been reported missing. Subsequently, an employee located the flash drive and returned it to his/her supervisor. The breach affected 544 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses/conditions, lab results, medications, and other treatment information. Upon discovering the breach, the CE notified OCR, the affected individuals, and media outlets. The breach was also reported to the New Jersey State Police Cyber Crimes Unit. As a result of the breach, the CE implemented new encryption technology for mobile data storage devices. The CE also revised its policies and procedures regarding employee access to PHI and PII, and retrained its employees. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 544 (as reported to HHS) |
|---|---|
| Disclosed | Feb 5, 2018 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): City of Detroit (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 5, 2018 | 544 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.