Skip to content

OptumHealth New Mexico

Disclosed Nov 18, 20169 years ago2,006 affectedConfirmed

Official notice

On September 26, 2016, the covered entity (CE), Optum, learned that an unencrypted portable computer drive (a "USB flash drive") containing the electronic protected health information (ePHI) of approximately 2,006 individuals had been lost or accidentally destroyed within the U.S. Postal Service System after being mailed on September 16, 2016 by Optum’s business associate (BA) Rothstein, Donatelli, Hughes, Dahlstrom, Schoenburg & Bienvenu (a law firm). The ePHI consisted of names, addresses, dates of birth, providers' names, diagnoses, plan ID, as well as partial or full social security numbers for 169 of the individuals. The CE's BA Agreement with the law firm is compliant with the Privacy Rule. As of January 1, 2017, the CE ceased engaging new business with the BA. OCR obtained documentation of this corrective action. OCR is opening a separate review of the BA.

What is known

People affected2,006 (as reported to HHS)
DisclosedNov 18, 2016
AttackLost or stolen device
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): OptumHealth New Mexico (Health Plan, MN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 18, 20162,006
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about OptumHealth New Mexico

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.