Back to the register

National Mentor Healthcare, LLC.

ArchivedSubmitted 03/21/2018
State
MA
Covered entity type
Healthcare Provider
Individuals affected
1,015
Business associate present
Yes
Type of breach
Loss
Location of breached information
Other Portable Electronic Device
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

A business associate (BA), Bullpen Financial, Inc., mailed an unencrypted portable computer drive (a “USB” drive) to the covered entity’s (CE’s) parent company as their business relationship was ending, but it was lost in the mail and not recovered. The lost USB drive contained the electronic protected health information (ePHI) of the CE’s consumers, including the demographic information of 1,015 individuals, and for some, clinical information. The CE’s parent company provided breach notification to HHS; the CE provided breach notification to affected individuals. Following the breach, the CE engaged an outside forensics firm to investigate and also entered into a BA agreement with its parent company, which is not a HIPAA covered entity. OCR provided technical assistance to the CE regarding the timeliness requirements of the breach notification rule, the definition of PHI, and the BA agreement requirements under the HIPAA Rules.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.