Rocky Mountain Women's Health Center
Disclosed Jan 25, 20188 years ago1,123 affectedConfirmed
On December 4, 2017, the covered entity (CE), Rocky Mountain Women’s Health Center, Inc., discovered that, on or about July 31, 2015, certain documents had been accidently left in office space that it no longer occupies. The CE stopped operating a clinic in the space in 2012, but its business associate (BA) used the space for billing and payment-related services on its behalf until July 31, 2015. The abandoned records contained 1,123 patients’ protected health information (PHI) and included paper records, receipts for payment, copies of checks, internal practice reports, and copies of medical records or other records that indicated diagnosis or medical history information. The types of PHI in these documents included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and offered a free year of credit monitoring. Following the breach, the CE revised its procedures for vacating space to include a final walk through to check for remaining charts or other patient information, trained staff with a focus on record retention and disposal, and developed a new record removal policy and procedure. OCR obtained ass
What is known
| People affected | 1,123 (as reported to HHS) |
|---|---|
| Disclosed | Jan 25, 2018 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Rocky Mountain Women's Health Center (Healthcare Provider, UT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 25, 2018 | 1,123 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.