Back to the register

MidMichigan Medical Center-Alpena

ArchivedSubmitted 12/19/2017
State
MI
Covered entity type
Healthcare Provider
Individuals affected
1,900
Business associate present
No
Type of breach
Loss
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On November 18, 2017, a physician employee removed patient files from the covered entity (CE), MidMichigan Medical Center-Alpena, and left them in a public parking lot in an unsecured container, which spilled out into the parking lot, and the wind subsequently scattered the records over several blocks. With the assistance of law enforcement, the CE attempted to retrieve the paper files. After the retrieved paper files were returned to the hospital in the broken storage container, the physician returned to the emergency department, discovered the items, stated that they were his, picked them up, and left the building. As the CE was unable to determine the exact records removed by the physician, the physician’s entire patient population of approximately 1,900 patients was potentially affected by the breach. The paper records contained patients’ names, addresses, Social Security numbers, and treatment information. The CE provided breach notification to HHS, the potentially affected individuals, and the media. Following the breach, the CE sanctioned the involved employee, retrained all employees, implemented mandatory training for new hires and annual training for current employees and health professionals, and required employees to sign a confidentiality agreement. The CE also designed and implemented a process for providers to use in aiding the investigation of potential breach matters and began transitioning to a paperless, one-system electronic medical record. OCR obtained documented assurances that the CE implemented these voluntary corrective actions. In this case the CE eventually terminated the employee responsible for the breach.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.