Back to the register
Memorial Hermann Health System, reporting on behalf of Memorial Hermann Health System Employee Group Health Plan
ArchivedSubmitted 07/20/2016
- State
- TX
- Covered entity type
- Health Plan
- Individuals affected
- 12,061
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Memorial Hermann Health System, reported that between December 12, 2015, and May 23, 2016, Memorial Hermann Health Solutions, the plan administrator for the Memorial Hermann Health System Employee Group Health Plan, impermissibly disclosed the protected health information (PHI) of 12,061 plan members to the CE’s primary care physicians (PCP). The disclosure included plan members’ names, addresses, dates of birth, telephone numbers and member identification. The plan members did not have an existing relationship with the PCP at the time of the disclosure, and therefore the disclosure was not for treatment purposes. The error occurred while implementing a new process in 2014, which was not effectively communicated to the leadership of the Health Plan. The CE met with the new leadership of the Health Plan to ensure the plan complies with its obligations to control data flow and to ensure the plan’s appropriate use of shared data. Following the incident, the CE provided evidence it notified affected individuals, the media, and posted substitute notification on its website.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.