Skip to content

Medcenter One

Disclosed Nov 17, 201114 years ago650 affectedConfirmed

Official notice

On or about October 21, 2011, the covered entity (CE), MedCenter One, Inc., which merged with Sanford Health on July 3, 2012, failed to safeguard the electronic protected health information (ePHI) of approximately 650 patients when an unencrypted, password-protected laptop computer and a bag containing 11 patient charge tickets were stolen from an employee’s vehicle. The type of ePHI involved in the breach included demographic information. The CE provided breach notification to HHS, affected individuals, and the media. The CE encrypted all of its laptop computers, implemented new information technology security policies and procedures, retrained staff on its new policies, and sanctioned the responsible employee. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected650 (as reported to HHS)
DisclosedNov 17, 2011
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Medcenter One (Healthcare Provider, ND)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 17, 2011650
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Medcenter One

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.