Skip to content

City of Detroit

Disclosed Feb 5, 20188 years ago544 affectedConfirmed

Official notice

The covered entity (CE), City of Detroit, reported that an unencrypted flash drive containing protected health information (PHI) had been reported missing. Subsequently, an employee located the flash drive and returned it to his/her supervisor. The breach affected 544 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses/conditions, lab results, medications, and other treatment information. Upon discovering the breach, the CE notified OCR, the affected individuals, and media outlets. The breach was also reported to the New Jersey State Police Cyber Crimes Unit. As a result of the breach, the CE implemented new encryption technology for mobile data storage devices. The CE also revised its policies and procedures regarding employee access to PHI and PII, and retrained its employees. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected544 (as reported to HHS)
DisclosedFeb 5, 2018
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): City of Detroit (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 5, 2018544
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about City of Detroit

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.