Memphis VA Medical Center
Disclosed Mar 1, 20179 years ago687 affectedConfirmed
Memphis VA Medical Center (MVAMC), the covered entity (CE), impermissibly disclosed protected health information (PHI) due to a printing format change that caused the wrong names to be associated with addresses in a survey mailed to its members. The breach incident included the names and addresses of 687 individuals. The CE provided breach notification to affected individuals and the media. The CE conducted a full review of the incident, re-educated staff regarding the appropriate methods for handling, securing, and mailing of PHI, set up a new process to prevent similar situations from re-occurring, and counseled and retrained the staff on its Privacy/Release of Information policy. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 687 (as reported to HHS) |
|---|---|
| Disclosed | Mar 1, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Memphis VA Medical Center (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 1, 2017 | 687 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.