Back to the register
Colorado Department of Human Services, Office of Behavioral Health
ArchivedSubmitted 04/07/2020
- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 8,132
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Colorado Department of Human Services, Office of Behavioral Health, the covered entity (CE), reported that the electronic protected health information (ePHI) of 8,132 individuals was accessible to unauthorized staff members. The ePHI involved included names, addresses, birthdates, Social Security numbers, claims information, financial information, diagnoses/conditions, and other treatment information. The CE determined that the ePHI was not publicly accessible; there was no evidence that its staff members improperly viewed, acquired, or used the PHI. OCR provided the CE with technical assistance regarding what constitutes a breach under the HIPAA Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.