Skip to content

Conway Regional Medical Center

Disclosed Oct 21, 201114 years ago1,472 affectedConfirmed

Official notice

A business associate (BA) of the covered entity (CE), Conway Regional Medical Center, sent the CE two compact disks containing scanned medical records which were mislaid following receipt. The protected health information (PHI) involved in the breach included the demographic and financial information of 1,472 individuals. The CE provided breach notification to HHS, the media, and affected individuals. Following this breach, the CE instructed its BA to encrypt any removable media that contains PHI and hand deliver the removable media to the CE’s Medical Records Department. Further, the CE improved administrative safeguards by updating its policy and procedures, which now requires a signature of an employee in the receiving department when packages are delivered. Also, all workforce members in the department involved in the breach attended additional HIPAA training. As a result of OCR’s investigation, the CE no longer routinely sends PHI off site for scanning.

What is known

People affected1,472 (as reported to HHS)
DisclosedOct 21, 2011
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 21, 20111,472
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Conway Regional Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.