Western Health Screening
Disclosed Apr 14, 20179 years ago15,326 affectedConfirmed
Western Health Screening contracts with hospitals to provide onsite blood screenings at hospital-sponsored health fairs. On February 7, 2017, while one of the its employees was en route to a health fair, a portable electronic storage device (a "jump drive") containing unsecured electronic protected health information (ePHI) and five laptop computers were stolen from the employee’s car. The laptops were encrypted, but the jump drive was not. The types of ePHI involved in the breach included the names, addresses, zip codes and social security numbers of 15,326 patients. Western Health provided breach notification to HHS, affected individuals and the media. Following the breach Western Health sanctioned the employee who was involved, retrained employees, and encrypted all of its jump drives. OCR obtained assurances that Western Health implemented the corrective actions noted above.
What is known
| People affected | 15,326 (as reported to HHS) |
|---|---|
| Disclosed | Apr 14, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Western Health Screening (Business Associate, MT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 14, 2017 | 15,326 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.