Skip to content

Missouri Department of Mental Health

Disclosed Oct 24, 20187 years ago9,000 affectedConfirmed

Official notice

The Missouri Department of Mental Health, the covered entity (CE), discovered that a former private contractor of its business associate (BA), had placed private client data in an unsecured cloud storage portal. The breach lasted from March 17, 2018, through August 31, 2018, and affected approximately 9,000 individuals. The CE notified all affected individuals, the media, and OCR. The CE mitigated the effects of the breach by confirming that the data had been removed from the cloud storage portal and obtained written verification from all parties involved in identifying the breach that they had either destroyed the data, securely returned the data, or that they are securely retaining the data for chain of custody purposes. During the investigation, OCR provided the CE with technical assistance regarding the risk analysis and risk management provisions of the Security Rule.

What is known

People affected9,000 (as reported to HHS)
DisclosedOct 24, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalOct 24, 20189,000

Other breaches at Missouri Department of Mental Health

BreachAffected
Disclosed Nov 8, 2024Nov 8, 20241 year agoInsider537
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Missouri Department of Mental Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.