- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,015
- Business associate present
- Yes
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business associate (BA), Bullpen Financial, Inc., mailed an unencrypted portable computer drive (a “USB” drive) to the covered entity’s (CE’s) parent company as their business relationship was ending, but it was lost in the mail and not recovered. The lost USB drive contained the electronic protected health information (ePHI) of the CE’s consumers, including the demographic information of 1,015 individuals, and for some, clinical information. The CE’s parent company provided breach notification to HHS; the CE provided breach notification to affected individuals. Following the breach, the CE engaged an outside forensics firm to investigate and also entered into a BA agreement with its parent company, which is not a HIPAA covered entity. OCR provided technical assistance to the CE regarding the timeliness requirements of the breach notification rule, the definition of PHI, and the BA agreement requirements under the HIPAA Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.