- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 687
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Memphis VA Medical Center (MVAMC), the covered entity (CE), impermissibly disclosed protected health information (PHI) due to a printing format change that caused the wrong names to be associated with addresses in a survey mailed to its members. The breach incident included the names and addresses of 687 individuals. The CE provided breach notification to affected individuals and the media. The CE conducted a full review of the incident, re-educated staff regarding the appropriate methods for handling, securing, and mailing of PHI, set up a new process to prevent similar situations from re-occurring, and counseled and retrained the staff on its Privacy/Release of Information policy. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.