Skip to content

Rocky Mountain Women's Health Center

Disclosed Jan 25, 20188 years ago1,123 affectedConfirmed

Official notice

On December 4, 2017, the covered entity (CE), Rocky Mountain Women’s Health Center, Inc., discovered that, on or about July 31, 2015, certain documents had been accidently left in office space that it no longer occupies. The CE stopped operating a clinic in the space in 2012, but its business associate (BA) used the space for billing and payment-related services on its behalf until July 31, 2015. The abandoned records contained 1,123 patients’ protected health information (PHI) and included paper records, receipts for payment, copies of checks, internal practice reports, and copies of medical records or other records that indicated diagnosis or medical history information. The types of PHI in these documents included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and offered a free year of credit monitoring. Following the breach, the CE revised its procedures for vacating space to include a final walk through to check for remaining charts or other patient information, trained staff with a focus on record retention and disposal, and developed a new record removal policy and procedure. OCR obtained ass

What is known

People affected1,123 (as reported to HHS)
DisclosedJan 25, 2018
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 25, 20181,123
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Rocky Mountain Women's Health Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.