Skip to content

Veterans Health Administration

Disclosed Nov 6, 20187 years ago19,254 affectedConfirmed

Official notice

On August 8, 2018, and September 4, 2018, the covered entity's (CE’s) business associate (BA), Xerox Corporation, erroneously printed appointment reminder cards for patients that were mailed to another patient. The two incidents affected a total of 19,254 individuals and included demographic and clinical information. The CE/BA provided breach notification to HHS, affected individuals, and the media. To protect against any other printing misalignment incident, the BA instituted additional processes and preventative measures such as joint BA and CE review of templates and programming prior to printing and a match alert notification. OCR reviewed a copy of the BA agreement, the individual breach notification letter, as well as the security measures implemented to address risks and vulnerabilities. OCR obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected19,254 (as reported to HHS)
DisclosedNov 6, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 6, 201819,254

Other breaches at Veterans Health Administration

BreachAffected
Disclosed Jan 5, 2024Jan 5, 20242 years agoInsider47K
Disclosed Sep 14, 2020Sep 14, 20206 years agoHacking44K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Veterans Health Administration

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.