- State
- MO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 836
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), SSM Health (SSMH), discovered that between April 12, 2017 and April 13, 2017, a component of an electromyography (EMG) medical device was stolen from the DePaul Hospital Clinic of Dr. Sayed Khader of the SSMH Medical Group. The stolen device stored protected health information (PHI), including 836 patients' first and last names, dates of birth, chief complaints, and medical record numbers. The CE provided breach notification to HHS, affected individuals, and the media and provided substitute notice. Following the breach, the CE updated its policies and procedures relating to safeguarding PHI, retrained its workforce, encrypted the medical device, and improved safeguards. In May 2018, OCR obtained evidence of the CE's updated system wide Risk Analysis and Risk Management Plan. OCR obtained documented assurances that the CE implemented the voluntary corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.