- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,123
- Business associate present
- No
- Type of breach
- Improper Disposal
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On December 4, 2017, the covered entity (CE), Rocky Mountain Women’s Health Center, Inc., discovered that, on or about July 31, 2015, certain documents had been accidently left in office space that it no longer occupies. The CE stopped operating a clinic in the space in 2012, but its business associate (BA) used the space for billing and payment-related services on its behalf until July 31, 2015. The abandoned records contained 1,123 patients’ protected health information (PHI) and included paper records, receipts for payment, copies of checks, internal practice reports, and copies of medical records or other records that indicated diagnosis or medical history information. The types of PHI in these documents included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and offered a free year of credit monitoring. Following the breach, the CE revised its procedures for vacating space to include a final walk through to check for remaining charts or other patient information, trained staff with a focus on record retention and disposal, and developed a new record removal policy and procedure. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.