- State
- MN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,304
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Open Cities Health Center, reported that an employee impermissibly transmitted electronic protected health information (ePHI) via the Internet to its business associate (BA). The breach affected approximately 1,304 individuals. The ePHI involved included names and dates of birth. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In response to the breach, the CE sanctioned the responsible employee, revised its policies and procedures, and retrained its workforce members on the proper methods of transmitting ePHI. OCR provided technical assistance to the CE regarding the Breach Notification Rule and obtained assurances that the CE implemented the corrective actions noted.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.