Skip to content

Mind Springs Health

Disclosed Feb 27, 201610 years ago2,147 affectedConfirmed

Official notice

On January 8, 2016 a foreign transcription services subcontractor to Mind Springs Health’s former business associate (BA), Stratton Consulting Services, Inc., mistakenly published electronic protected health information (ePHI) on the internet during a software update. The types of ePHI involved in the breach included names, dates of birth, medications, and physicians’ notes, affecting 2,147 individuals who received treatment from the covered entity (CE) between January 2009 and March 2010. Following the breach, the subcontractor removed the information from the internet. The CE provided breach notification to HHS, affected individuals, and the media. Subsequent to the breach, the CE established BA agreements with its contractors. OCR provided technical assistance regarding relevant issues pursuant to the Privacy and Security Rules.

What is known

People affected2,147 (as reported to HHS)
DisclosedFeb 27, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mind Springs Health (Healthcare Provider, CO)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 27, 20162,147
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mind Springs Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.