Mercy Medical Center- North Iowa
Disclosed Nov 26, 20187 years ago1,971 affectedConfirmed
The covered entity (CE), Mercy Medical Center – North Iowa, was notified by local law enforcement that a previous employee was under criminal investigation. While the employee was working for Mercy Medical Center, he/she impermissibly accessed the electronic protected health information (ePHI) of 1,971 employees. The ePHI involved included names, addresses, diagnoses, conditions, and medications prescribed. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE retrained its staff. In addition, the CE is in the process of implementing a new electronic medical record system that will allow the CE to install additional technical and security safeguards to better protect its ePHI.
What is known
| People affected | 1,971 (as reported to HHS) |
|---|---|
| Disclosed | Nov 26, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mercy Medical Center- North Iowa (Healthcare Provider, IA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 26, 2018 | 1,971 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.