Skip to content

Mentor ABI

Disclosed Mar 21, 20188 years ago994 affectedConfirmed

Official notice

A business associate (BA), Bullpen Financial, Inc., mailed an unencrypted portable computer drive (a “USB” drive) to the covered entity’s (CE’s) parent company as their business relationship was ending, but it was lost in the mail and not recovered. The lost USB drive contained the electronic protected health information (ePHI) of the CE’s consumers, including the demographic information of 994 individuals, and for some, clinical information. The CE’s parent company provided breach notification to HHS; the CE provided breach notification to affected individuals. Following the breach, the CE engaged an outside forensics firm to investigate and also entered into a BA agreement with its parent company, which is not a HIPAA covered entity. OCR provided technical assistance to the CE regarding the timeliness requirements of the breach notification rule, the definition of PHI, and the BA agreement requirements under the HIPAA Rules.

What is known

People affected994 (as reported to HHS)
DisclosedMar 21, 2018
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mentor ABI (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 21, 2018994
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mentor ABI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.