Back to the register

Memorial Hermann Health System, reporting on behalf of Memorial Hermann Health System Employee Group Health Plan

ArchivedSubmitted 07/20/2016
State
TX
Covered entity type
Health Plan
Individuals affected
12,061
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Memorial Hermann Health System, reported that between December 12, 2015, and May 23, 2016, Memorial Hermann Health Solutions, the plan administrator for the Memorial Hermann Health System Employee Group Health Plan, impermissibly disclosed the protected health information (PHI) of 12,061 plan members to the CE’s primary care physicians (PCP). The disclosure included plan members’ names, addresses, dates of birth, telephone numbers and member identification. The plan members did not have an existing relationship with the PCP at the time of the disclosure, and therefore the disclosure was not for treatment purposes. The error occurred while implementing a new process in 2014, which was not effectively communicated to the leadership of the Health Plan. The CE met with the new leadership of the Health Plan to ensure the plan complies with its obligations to control data flow and to ensure the plan’s appropriate use of shared data. Following the incident, the CE provided evidence it notified affected individuals, the media, and posted substitute notification on its website.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.