Saint Joseph - Berea
Disclosed Jun 2, 201115 years ago1,986 affectedConfirmed
The covered entity (CE), St. Joseph-Berea discovered that an external back-up hard drive attached to a workstation was missing. The external hard drive included the protected health information of 1,986 individuals, including patients’ names, dates of birth and information related to bone density scans. The CE provided breach notification to HHS, affected individuals, and the media and performed substitute notice by posting on its website. Following the breach, the CE updated its procedures to limit the use of external hard drives, encrypted all laptops, desktops, servers, and portable media devices, and improved safeguards by monitoring physical workstation access and maintaining observation cameras. As a result of OCR’s investigation, OCR obtained assurances that the corrective actions listed above were completed.
What is known
| People affected | 1,986 (as reported to HHS) |
|---|---|
| Disclosed | Jun 2, 2011 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Saint Joseph - Berea (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 2, 2011 | 1,986 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.