- State
- MO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 9,000
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The Missouri Department of Mental Health, the covered entity (CE), discovered that a former private contractor of its business associate (BA), had placed private client data in an unsecured cloud storage portal. The breach lasted from March 17, 2018, through August 31, 2018, and affected approximately 9,000 individuals. The CE notified all affected individuals, the media, and OCR. The CE mitigated the effects of the breach by confirming that the data had been removed from the cloud storage portal and obtained written verification from all parties involved in identifying the breach that they had either destroyed the data, securely returned the data, or that they are securely retaining the data for chain of custody purposes. During the investigation, OCR provided the CE with technical assistance regarding the risk analysis and risk management provisions of the Security Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.