Skip to content

SSM Dean Medical Group

Disclosed Jan 10, 20179 years ago4,800 affectedConfirmed

Official notice

The covered entity (CE), SSM Health, inadvertently sent email addressed to the wrong recipient patients due to an improperly sorted data file. The protected health information (PHI) involved in the breach included the full names of approximately 4,800 individuals. Following the breach, the CE attempted to provide breach notification to the affected individuals and provided media notification. During the course of its investigation, OCR discovered that the CE's notice to the affected individuals was not sent in accordance with the Breach Notification Rule because it sent electronic notice to without a prior agreement from the individuals to receive notice electronically. As a corrective action, the CE agreed to provide written notice to the affected individuals via first-class mail, in accordance with the Rule, and then provided OCR proof of such written notice. To prevent a similar breach from happening in the future, the CE instituted a procedural checklist to be followed for all mass email communications.

What is known

People affected4,800 (as reported to HHS)
DisclosedJan 10, 2017
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): SSM Dean Medical Group (Healthcare Provider, WI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalJan 10, 20174,800
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about SSM Dean Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.