Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
VA Midwest Health Care Network (VISN 23)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on June 14, 2011. Also cited in 183 other reports.
Report ID: SPE000000063683, U.S. Department of Veterans Affairs
Reported Entity: VISN 23 St. Cloud, MN
Issue:
A Human Resource HR Technician sent an internal VistA e-mail message to the wrong mail group. The message contained the full name, Date of Birth (DoB) and full SSN of a new employee. The group it was sent to contains 68 recipients rather than the small group of recipients who are to receive the full range of information on a new employee. Of the 68 recipients, 28 of them had read the message by the time the Privacy Officer (PO) was able to have the message terminated. Update: 06/14/11:The employee whose full name, DOB and full SSN was sent to the wrong mail group will be sent a letter offering credit protection services.
Outcome:
The HR Techs will now create a message that contains the limited and non-sensitive information to send to the large group of recipients and then will add the sensitive information to the second message which is sent to the four recipients.