- State
- SD
- Covered entity type
- Health Plan
- Individuals affected
- 1,632
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The Indian Health Service (IHS) reported than an employee of its business associate (BA), was observed copying and pasting medical records and then sending those documents to his personal email account. The protected health information (PHI) involved included names, social security numbers, dates of birth, and other demographic information. This breach incident affected 1,720 patients and occurred between March 1, 2013 and August 25, 2014. Upon learning of the physician’s actions, IHS immediately terminated his contract, notified all affected individuals and the media, and obtained written assurance from the physician that he deleted all of the medical records from his personal computer. As a result of OCR’s investigation and technical assistance, IHS developed policies and procedures for safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.