Young Adult Institute
Disclosed Nov 28, 20169 years ago913 affectedConfirmed
The covered entity's (CE) former Chief Information Officer instructed a former Assistant IT Director to copy files containing the protected health information (PHI) of 913 clients onto a portable computer drive. Subsequently, the former CIO took the drive with him to his new employer after he was terminated. The types of PHI involved in the breach included names, addresses, dates of birth, social security numbers, Medicaid numbers and diagnoses The CE provided breach notification to HHS, the affected individuals, and the media. As a result of OCR’s investigation, the CE revised its procedures with respect to assigning an approval process for access to removable media. In addition, the CE conducted a risk analysis and established a risk management plan to manage and reduce the risks identified in the risk analysis, including, but not limited to, access to removable drives. As a result of OCR's investigation it is expected to implement technical security measures to guard against unauthorized access to ePHI, and review and revise its policies and procedures and training materials regarding the Security Rule. Additionally, the CE is expected to execute HIPAA-compliant business associa
What is known
| People affected | 913 (as reported by the organization) |
|---|---|
| Disclosed | Nov 28, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2016 data breach report: Young Adult Institutein.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Young Adult Institute (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Nov 28, 2016 | 1 |
| HHS archivetotal | Nov 28, 2016 | 913 |
History of this record
- 2026-09-25 · sector: other to health · backfill source
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity's (CE) former Chief Information Officer instructed a former Assistant IT Director to copy files containing the protected health information (PHI) of 913 clients onto a portable computer drive. Subsequently, the former CIO · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.