WorkflowOne
Disclosed Jan 8, 201313 years ago635 affectedConfirmed
Due to a malfunction in processing benefit confirmation statements, employee information was comingled and statements were mailed to the wrong employees and dependents. The breach included the protected health information (PHI) of 635 individuals. The PHI involved in the breach included names and social security numbers. The covered entity (CE), Dimensions Healthcare System, provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE revised its correspondence handling procedures. As a result of OCR’s investigation, the CE reviewed its business associate (BA) relationships to ensure that appropriate BA agreements were in place.
What is known
| People affected | 635 (as reported to HHS) |
|---|---|
| Disclosed | Jan 8, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): WorkflowOne (Business Associate, OH)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jan 8, 2013 | 635 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.