Mercy Hospital Logan County
Disclosed Aug 30, 20179 years ago629 affectedConfirmed
On July 1, 2017, the covered entity (CE), Mercy Hospital Logan County, discovered that a binder was missing from its Laboratory Department that contained the protected health information (PHI) of 629 individuals. The PHI included patients’ names, medical record numbers, and information related to four clinical tests. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ceased manually recording patients’ test results in a binder and began entering them into its electronic system. Also, the CE implemented a procedure that restricts access to the laboratory and increased physical security for the laboratory. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 629 (as reported to HHS) |
|---|---|
| Disclosed | Aug 30, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mercy Hospital Logan County (Healthcare Provider, OK)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Aug 30, 2017 | 629 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.