- State
- ND
- Covered entity type
- Health Plan
- Individuals affected
- 2,452
- Business associate present
- No
- Type of breach
- Improper Disposal
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
North Dakota Department of Human Services, the covered entity (CE), reported a breach to HHS after it discovered that a workforce member had disposed of documents that included protected health information (PHI) in a dumpster. The documents contained PHI belonging to 2,452 individuals. The PHI included individuals’ first and last names, dates of birth, Medicaid provider numbers and other identifiers, dates of service, diagnosis codes, procedure codes, and billing information. The CE notified affected individuals and prominent media outlets of the breach. The CE also posted substitute notification on its website. The workforce member responsible for the breach resigned in lieu of termination. The CE trained its staff in proper disposal of PHI. As a result of OCR’s technical assistance, the CE revised its policies concerning safeguarding PHI, the provision of Privacy training, its sanctions policies, disclosures of PHI and its mitigation policy and provided OCR with written assurance that it will train all members of its workforce on the updated policies.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.