Skip to content

OhioHealth

Disclosed Jul 24, 201511 years ago1,006 affectedConfirmed

Official notice

On May 29, 2015, the covered entity (CE), OhioHealth, discovered that an unencrypted portable computer drive (‘thumb drive”) was missing. This breach affected approximately 1,006 individuals. The types of protected health information (PHI) involved in the breach included patients’ names, medical record numbers, names of insurance companies, addresses, dates of birth, physicians’ names, referral and treatment dates, type of procedures, and in certain limited instances, clinical information and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE sanctioned and retrained the employee who lost the thumb drive, suspended use of thumb drives in the involved department, and retrained employees. The CE also revised its policies on mobile storage device security and usage and on disposition of thumb drives. Additionally, the CE encrypted mobile storage devices and revised and launched annual compliance education for its employees. OCR obtained documentation that the CE implemented the corrective actions steps noted above.

What is known

People affected1,006 (as reported to HHS)
DisclosedJul 24, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): OhioHealth (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJul 24, 20151,006

Other breaches at OhioHealth

BreachAffected
Disclosed Jan 4, 2011Jan 4, 201115 years agoLost or stolen device501
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about OhioHealth

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.