MidMichigan Medical Center-Alpena
Disclosed Dec 19, 20178 years ago1,900 affectedConfirmed
On November 18, 2017, a physician employee removed patient files from the covered entity (CE), MidMichigan Medical Center-Alpena, and left them in a public parking lot in an unsecured container, which spilled out into the parking lot, and the wind subsequently scattered the records over several blocks. With the assistance of law enforcement, the CE attempted to retrieve the paper files. After the retrieved paper files were returned to the hospital in the broken storage container, the physician returned to the emergency department, discovered the items, stated that they were his, picked them up, and left the building. As the CE was unable to determine the exact records removed by the physician, the physician’s entire patient population of approximately 1,900 patients was potentially affected by the breach. The paper records contained patients’ names, addresses, Social Security numbers, and treatment information. The CE provided breach notification to HHS, the potentially affected individuals, and the media. Following the breach, the CE sanctioned the involved employee, retrained all employees, implemented mandatory training for new hires and annual training for current employees and
What is known
| People affected | 1,900 (as reported to HHS) |
|---|---|
| Disclosed | Dec 19, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): MidMichigan Medical Center-Alpena (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 19, 2017 | 1,900 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.