OptumHealth New Mexico
Disclosed Nov 18, 20169 years ago2,006 affectedConfirmed
On September 26, 2016, the covered entity (CE), Optum, learned that an unencrypted portable computer drive (a "USB flash drive") containing the electronic protected health information (ePHI) of approximately 2,006 individuals had been lost or accidentally destroyed within the U.S. Postal Service System after being mailed on September 16, 2016 by Optum’s business associate (BA) Rothstein, Donatelli, Hughes, Dahlstrom, Schoenburg & Bienvenu (a law firm). The ePHI consisted of names, addresses, dates of birth, providers' names, diagnoses, plan ID, as well as partial or full social security numbers for 169 of the individuals. The CE's BA Agreement with the law firm is compliant with the Privacy Rule. As of January 1, 2017, the CE ceased engaging new business with the BA. OCR obtained documentation of this corrective action. OCR is opening a separate review of the BA.
What is known
| People affected | 2,006 (as reported to HHS) |
|---|---|
| Disclosed | Nov 18, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): OptumHealth New Mexico (Health Plan, MN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 18, 2016 | 2,006 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.