- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,915
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 19, 2017, Mann-Grandstaff VA Medical Center, the covered entity (CE), reported that two portable hard drives containing protected health information (PHI had been stolen from its business associate (BA) on July 18, 2017. The types of PHI involved in the incident included the names, addresses, social security numbers, phone numbers, surgical information, and insurance information of 1,915 individuals. The CE provided breach notification to affected individuals, the media, and HHS. The CE conducted an investigation, and contacted the police about the incident. As a result of this incident, the CE ensured the BA took corrective actions and the CE developed and implemented new media sanitization policies to ensure the proper destruction of PHI stored on electronic devices.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.