- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,719
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Myriad Genetic Laboratories (MGL), the covered entity (CE), reported that a workforce member mistakenly emailed a spreadsheet containing protected health information (PHI) to a patient. The PHI involved included names, telephone numbers, medical record numbers, treatment information, and claims information. The breach affected 1,719 individuals. MGL notified all affected individuals and OCR. The covered entity sanctioned the workforce member responsible for the breach. It revised its policy and implemented changes to protect sensitive data when using email communications. It re-trained all workforce members on the updated policy. In addition, the covered entity provided documentation that it has a security awareness and training program in place for all workforce members.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.