- State
- PR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 32,390
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Thieves broke into the MMM Healthcare, Inc. facility located in Humacao, Puerto Rico and stole four unencrypted desktop computers containing 32,390 health plan members’ electronic protected health information (ePHI). The ePHI stored in the stolen computers included names, addresses, phone numbers, Medicare numbers, diagnosis and treatment information, health plan names, health plan member identification numbers, health plan enrollment information, health care claim information, and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE repaired a damaged wall and improved physical security for the facility and the surrounding premises. As a result of OCR’s investigation, the CE encrypted all computers located at its regional offices. OCR obtained assurances that the CE implemented the corrective actions listed above. Additionally, OCR stated its expectation that the CE will perform a thorough and accurate risk analysis and establish a risk management plan. In addition, OCR stated its expectation that the CE will implement contingency operations procedures, implement its security policies and procedures, and regularly patch and update its IT infrastructure. OCR stated an expectation for the CE to encrypt ePHI where appropriate, and document the technical safeguards implemented to prohibit the unauthorized copying and removal of PHI and ePHI from the premises.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.