- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,182
- Business associate present
- No
- Type of breach
- Other
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A workforce member of the covered entity (CE), Robley Rex VA Medical Center, lost or had stolen a binder of coding reports, which contained the protected health information (PHI) of 1,182 individuals. The binder was left unattended outside the entrance of the facility and returned soon thereafter to a workforce member by an inpatient at the facility who discovered the log book. The PHI involved in the breach included PHI of approximately 1,182 individuals, including names, social security numbers, and discharge dates. The CE provided breach notification to HHS, affected individuals, and the media, and offered free credit protection to all affected individuals. Following the breach, the CE suspended the employee, sent a bulletin to all employees indicating that they were not permitted to maintain log books or transport PHI outside the facility without authorization. As a result of OCR’s investigation, the CE reviewed its policies and procedures to ensure the adequacy of safeguards.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.