- State
- AL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 652
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 25, 2017, the Viral Hepatitis Clinic at University of Alabama at Birmingham, the covered entity (CE), lost two unencrypted portable computer drives (i.e., "thumb" drives) that were used to transfer data from scanning equipment to the CE’s secure network. The thumb drives contained the protected health information (PHI) of 652 individuals in a spreadsheet containing demographic and clinical information. The CE retrieved the thumb drives, but could not determine whether the PHI contained on the thumb drives had or had not been viewed. In response to this incident and OCR’s investigation, the CE staff responsible for the lost thumb drives were counselled and reprimanded. The CE provided breach notification to HHS, the affected individuals and the media. The CE also implemented a new procedure, eliminating the need to use thumb drives to transfer data to and from the scanning equipment. It developed a written policy regarding the new procedure, the use of portable devices, and the security of data within the clinic. All relevant staff participated in HIPAA re-training, and training on the new policy and procedure. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.