- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,711
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A physician of the CE lost a flash drive which he routinely used for data backup and remote access to patient data. The flash drive contained names, dates of birth and treatment notes for approximately 1,711 patients. Following the breach, the CE notified affected individuals. The CE retrained the physician who lost the flash drive and implemented an organization-wide decision to prohibit storage of protected health information on any removable electronic devices. As a result of OCR’s investigation, the CE notified the media and posting substitute notification on its website.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.