- State
- MN
- Covered entity type
- Health Plan
- Individuals affected
- 2,006
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On September 26, 2016, the covered entity (CE), Optum, learned that an unencrypted portable computer drive (a "USB flash drive") containing the electronic protected health information (ePHI) of approximately 2,006 individuals had been lost or accidentally destroyed within the U.S. Postal Service System after being mailed on September 16, 2016 by Optum’s business associate (BA) Rothstein, Donatelli, Hughes, Dahlstrom, Schoenburg & Bienvenu (a law firm). The ePHI consisted of names, addresses, dates of birth, providers' names, diagnoses, plan ID, as well as partial or full social security numbers for 169 of the individuals. The CE's BA Agreement with the law firm is compliant with the Privacy Rule. As of January 1, 2017, the CE ceased engaging new business with the BA. OCR obtained documentation of this corrective action. OCR is opening a separate review of the BA.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.