Henry Ford Health System
ent_019e0acd83f19135a229892298489553
Disclosures
10
HHS OCR · State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
168,215
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Henry Ford Health System
- Normalized
- henry ford health system— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- I4VJ7V7BFJ03TC4T1I41
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- henryford.com
Disclosure history (10)newest first
- MIHHS OCRas victim2025-11-26
Henry Ford Health reported to HHS on 2025-11-26 a Unauthorized Access/Disclosure affecting 1984 individuals. Breached information located on Desktop Computer.
- 🦞Maine State AGas victim2023-07-25
Henry Ford Health reported an external system breach (hacking) occurring on March 30, 2023, discovered on May 16, 2023. The incident affected 168,215 individuals, including 2 Maine residents. The breach involved the acquisition of personal identifiers. Written notification was sent to affected individuals on July 14, 2023.
- MIHHS OCRas victim2023-06-06
Henry Ford Health reported to HHS on 2023-06-06 a Hacking/IT Incident affecting 168215 individuals. Breached information located on Email. The web description references Brigham and Women's Hospital and graphs posted to the Internet containing links exposing PHI (names, birthdates, diagnoses, lab results, medications). Response included notifying HHS, individuals, and media, and implementing safeguards.
- MIHHS OCRas victim2019-06-19
Henry Ford Health System reported to HHS on 2019-06-19 a Unauthorized Access/Disclosure affecting 1404 individuals. Breached information located on Email. An employee inadvertently sent an email containing PHI (names, DOB, medical conditions, lab results) to an incorrect address. HFHS retrained employees and implemented additional safeguards.
- MIHHS OCRas victim2019-02-20
Henry Ford Health System (HFHS) reported to HHS on 2019-02-20 an Unauthorized Access/Disclosure affecting 5,590 individuals. An employee inadvertently mailed PHI (names and medication information) to the wrong recipients. Breached information was located in Paper/Films. The CE notified HHS, affected individuals, and media. Corrective actions included administrative safeguards, staff retraining, and OCR-guided harm mitigation (recipients asked to destroy/return incorrectly received mailings). OCR obtained assurances of compliance.
- MIHHS OCRas victim2018-04-10
Henry Ford Health System reported to HHS on 2018-04-10 a Loss affecting 1658 individuals. Breached information located on Other Portable Electronic Device. An employee lost an unencrypted flash drive containing PHI (names, DOB, lab results, treatment info). The CE notified HHS, individuals, media, and posted substitute notice. The responsible employee was sanctioned and retrained.
- MIHHS OCRas victim2017-12-01
Henry Ford Health System reported to HHS on 2017-12-01 a Hacking/IT Incident affecting 43,563 individuals. Breached information located on Email. The breach involved an email phishing scheme exposing PHI including names, DOB, MRNs, SSNs, and treatment info. The CE provided credit monitoring, implemented safeguards, and retrained staff.
- MIHHS OCRas victim2017-06-26
Henry Ford Health System (Troy, MI) reported to HHS on 2017-06-26 a Theft affecting 596 individuals. On May 18, 2017, Troy, Michigan police informed the covered entity that paper-form PHI — old patient face sheets containing demographic and clinical information — was found in a storage unit belonging to a suspected identity thief. The CE notified HHS, affected individuals, and the media, retrieved all face sheets from police, and implemented an active access monitoring tool. OCR obtained documented assurances of corrective action.
- MIHHS OCRas victim2015-01-09
Henry Ford Health System (MI) reported to HHS OCR on 2015-01-09 a Loss breach affecting 2,336 individuals. On October 23, 2014, a physician lost a personal (non-employer-issued) USB flash drive containing PHI — clinical and demographic information — in violation of CE policy requiring employer-issued encrypted flash drives. The CE sanctioned the employee, notified affected individuals and media, and provided OCR with written assurances of corrective actions including an enhanced asset management program and enterprise data mapping. Breached information was located on a portable electronic device.
- MIHHS OCRas victim2011-10-03
Henry Ford Health System reported to HHS on 2011-10-03 a Theft affecting 520 individuals. Breached information located on Desktop Computer.