National Mentor Healthcare
Disclosed Mar 21, 20188 years ago1,015 affectedConfirmed
A business associate (BA), Bullpen Financial, Inc., mailed an unencrypted portable computer drive (a “USB” drive) to the covered entity’s (CE’s) parent company as their business relationship was ending, but it was lost in the mail and not recovered. The lost USB drive contained the electronic protected health information (ePHI) of the CE’s consumers, including the demographic information of 1,015 individuals, and for some, clinical information. The CE’s parent company provided breach notification to HHS; the CE provided breach notification to affected individuals. Following the breach, the CE engaged an outside forensics firm to investigate and also entered into a BA agreement with its parent company, which is not a HIPAA covered entity. OCR provided technical assistance to the CE regarding the timeliness requirements of the breach notification rule, the definition of PHI, and the BA agreement requirements under the HIPAA Rules.
What is known
| People affected | 1,015 (as reported to HHS) |
|---|---|
| Disclosed | Mar 21, 2018 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): National Mentor Healthcare (Healthcare Provider, MA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 21, 2018 | 1,015 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.