Skip to content

Valley Mental Health

Disclosed Apr 26, 201313 years ago700 affectedConfirmed

Official notice

On February 27, 2013, Valley Mental Health, the covered entity (CE), discovered that a computer hard drive had been stolen from one of its facilities. The computer was located in a common area and available for use by members. The hard drive contained protected health information (PHI)—members' names, diagnostic and treatment information, financial records, media release forms, members' photographs, activity sign-up sheets, and resumes—for approximately 700 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach and during OCR’s investigation, the CE posted signs reminding members that information stored on shared computers is not confidential, encrypted hard drives, and stored PHI in locked offices and locked file cabinets. OCR obtained assurances that the CE implemented the corrective actions listed above, and OCR provided the CE with technical assistance regarding its Security Rule obligations.

What is known

People affected700 (as reported to HHS)
DisclosedApr 26, 2013
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Valley Mental Health (Healthcare Provider, UT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 26, 2013700
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Valley Mental Health

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.