SSM Dean Medical Group
Disclosed Jan 10, 20179 years ago4,800 affectedConfirmed
The covered entity (CE), SSM Health, inadvertently sent email addressed to the wrong recipient patients due to an improperly sorted data file. The protected health information (PHI) involved in the breach included the full names of approximately 4,800 individuals. Following the breach, the CE attempted to provide breach notification to the affected individuals and provided media notification. During the course of its investigation, OCR discovered that the CE's notice to the affected individuals was not sent in accordance with the Breach Notification Rule because it sent electronic notice to without a prior agreement from the individuals to receive notice electronically. As a corrective action, the CE agreed to provide written notice to the affected individuals via first-class mail, in accordance with the Rule, and then provided OCR proof of such written notice. To prevent a similar breach from happening in the future, the CE instituted a procedural checklist to be followed for all mass email communications.
What is known
| People affected | 4,800 (as reported to HHS) |
|---|---|
| Disclosed | Jan 10, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): SSM Dean Medical Group (Healthcare Provider, WI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 10, 2017 | 4,800 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.