Memorial Healthcare
Disclosed Apr 3, 20179 years ago685 affectedConfirmed
Memorial Healthcare, the covered entity (CE), reported that its business associate (BA), RevSpring, inadvertently mailed protected health information (PHI) to the wrong recipients. This breach affected approximately 685 individuals. The PHI involved included names, account information, treatment information, and financial information. The CE notified HHS, affected individuals, and the media. Credit monitoring services were offered to all affected individuals and the BA implemented administrative safeguards to better protect its PHI. As a result of OCR’s investigation, the CE revised its BA agreement. OCR obtained assurances that the CE and BA implemented the corrective actions noted above.
What is known
| People affected | 685 (as reported to HHS) |
|---|---|
| Disclosed | Apr 3, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Memorial Healthcare (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 3, 2017 | 685 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.