Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
VA Southeast Network (VISN 7)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on November 20, 2012. Also cited in 225 other reports.
Report ID: PSETS0000082705, U.S. Department of Veterans Affairs
Reported Entity: VISN 07 Augusta, GA
Issue:
An employee reported that she sent an email that was intended for a VA employee; however, the email somehow ended up being sent to a Veteran's personal email address. The Veteran emailed the employee back indicating that it was sent in error. The email contained full name, last four of SSN, appointment time, and clinic for 14 patients. The Information Security Officer advised the employee that this could have been avoided if the email were encrypted and instructed the employee to delete the unencrypted email from her inbox and deleted items folder. Update: 11/20/12:Fourteen (14) Veterans will be sent a notification letter due to Protected Health Information being disclosed.
Outcome:
The ISO advised the employee that this could have been avoided if the email were encrypted and instructed the employee to delete the unencrypted email from her inbox and deleted items folder.