Medcenter One
Disclosed Nov 17, 201114 years ago650 affectedConfirmed
On or about October 21, 2011, the covered entity (CE), MedCenter One, Inc., which merged with Sanford Health on July 3, 2012, failed to safeguard the electronic protected health information (ePHI) of approximately 650 patients when an unencrypted, password-protected laptop computer and a bag containing 11 patient charge tickets were stolen from an employee’s vehicle. The type of ePHI involved in the breach included demographic information. The CE provided breach notification to HHS, affected individuals, and the media. The CE encrypted all of its laptop computers, implemented new information technology security policies and procedures, retrained staff on its new policies, and sanctioned the responsible employee. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 650 (as reported to HHS) |
|---|---|
| Disclosed | Nov 17, 2011 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Medcenter One (Healthcare Provider, ND)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 17, 2011 | 650 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.