Family Health Services Minnesota
Disclosed May 14, 201214 years ago4,000 affectedConfirmed
On March 20, 2012, one of the covered entity's (CE) clinic locations in St. Paul, Minnesota, was burglarized and two tablet computers containing electronic protected health information (ePHI) were stolen. The computers contained demographic information for approximately 4,000 individuals. Upon discovering the breach, the CE, Family Health Services' of Minnesota, P.A., reported the breach incident to the Saint Paul Police Department. The CE also provided breach notification to the individuals affected by the breach, HHS, and the media. To prevent similar breaches from happening in the future, the CE improved safeguards for storage of its laptop computers and encrypted its computer hard drives. The CE also conducted a security risk analysis, prepared an incident report, and updated its policy and procedure regarding the safeguarding of PHI, and trained its workforce on its updated policies and procedures. OCR obtained documented assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 4,000 (as reported to HHS) |
|---|---|
| Disclosed | May 14, 2012 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Family Health Services Minnesota (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 14, 2012 | 4,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.