Skip to content

Spectrum Health System

Disclosed Aug 3, 20179 years ago902 affectedConfirmed

Official notice

On June 22, 2017, a digital camera with stored photographs of patients’ chart labels and photographs of patients’ skin conditions was stolen out of a physician’s vehicle which was parked outside the physician’s home. The stolen camera contained protected health information (PHI) created between February 15, 2017, and June 21, 2017, including 902 individuals’ demographic and clinical information. The physician reported the theft to law enforcement. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media, posted substitute notice on its website, and established a call center to answer patients’ questions and public inquiries. Following the breach, the CE updated its policies and procedures for safeguarding PHI on mobile devices, requiring employees to install encryption software on all CE-approved cell phones and mobile devices and banning the removal of cameras and camera memory cards from the CE’s premises. The CE also trained workforce members on securely capturing and storing electronic PHI on mobile devices. In October 2018, the CE began a comprehensive enterprise wide risk analysis that continued into 2019. OCR obtained documented assura

What is known

People affected902 (as reported to HHS)
DisclosedAug 3, 2017
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Spectrum Health System (Healthcare Provider, MI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 3, 2017902

Other breaches at Spectrum Health System

BreachAffected
Disclosed Apr 15, 2022Apr 15, 20224 years agoInsider794
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Spectrum Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.