Indian Health Service -Rosebud
Disclosed Jul 15, 201412 years ago620 affectedConfirmed
The covered entity (CE), Indian Health Service IHS), Rosebud Service Unit, reported that on May 30, 2014, its employee left a folder of records containing protected health information (PHI) in a public restroom at the IHS’ Rapid City Hospital when she was at the hospital for a meeting. The folder contained the records of 620 individuals and included patient names and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media and also offered credit monitoring and identity theft insurance to affected individuals. Following the breach, the CE sanctioned the employee. OCR obtained written assurances from the CE that it will implement policies and procedures regarding breach notification and mitigation in accordance with the technical assistance provided by OCR pursuant to this investigation.
What is known
| People affected | 620 (as reported to HHS) |
|---|---|
| Disclosed | Jul 15, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Indian Health Service -Rosebud (Healthcare Provider, MD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 15, 2014 | 620 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.