Back to the register
The Kroger Co., for itself and its affiliates and subsidiaries
ArchivedSubmitted 10/25/2019
- State
- OH
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,812
- Business associate present
- Yes
- Type of breach
- Loss
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), The Kroger Company, reported that a shipping service lost a box of patient records containing the protected health information (PHI) of approximately 4,812 individuals. The records were being shipped from its off-site storage facility; however, the off-site storage vendor shipped more than the PHI requested. The PHI involved included names, prescription numbers, and health insurance information. The CE notified HHS, affected individuals, the media, and provided a toll-free number for questions or concerns. The CE implemented additional administrative safeguards and retrained its staff. OCR obtained documentation that the CE implemented the corrective actions noted.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.