Ohio Department of Mental Health and Addiction Services
Disclosed Apr 22, 201610 years ago59,000 affectedConfirmed
The covered entity (CE), Ohio Department of Mental Health and Addiction Services, reported that postcards containing protected health information (PHI) were mailed to patients and/or their families. The PHI involved included names, addresses, and treatment information. The postcards were mailed to approximately 54,000 individuals. The CE notified HHS, affected individuals, and the media. As a result of this breach, the CE halted further mailings of postcards containing sensitive information. The CE also adopted additional administrative safeguards to further protect its PHI and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 59,000 (as reported to HHS) |
|---|---|
| Disclosed | Apr 22, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Ohio Department of Mental Health and Addiction Services (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 22, 2016 | 59,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Ohio Department of Mental Health and Addiction Services