Missouri Dept. of Mental Health
ent_150961148de79b5ba77b2539
Disclosures
4
HHS OCR · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
9,000
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Missouri Dept. of Mental Health
- Normalized
- missouri dept of mental health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- FEDERALHHS OCRas victim2024-11-08
Missouri Department of Mental Health reported that an employee erroneously sent an unencrypted email containing the protected health information (PHI) of 537 individuals to the wrong recipients. The PHI included names, Social Security numbers, addresses, and dates of birth. The incident was reported to HHS on November 8, 2024. In response, the department implemented additional safeguards and retrained staff.
- FEDERALHHS OCRas victim2018-10-24
The Missouri Department of Mental Health reported that a former contractor of its business associate placed private client data in an unsecured cloud storage portal. The breach occurred between March 17, 2018, and August 31, 2018, affecting approximately 9,000 individuals. In response, the department confirmed the data was removed from the portal and obtained written verification that the data was destroyed or returned. The Office for Civil Rights (OCR) provided technical assistance to the department regarding security risk analysis and management.
- MOHHS OCRas victim2018-02-21
Missouri Dept. of Mental Health reported to HHS on 2018-02-21 a Unauthorized Access/Disclosure affecting 1000 individuals. Breached information located on Other. The covered entity erroneously mailed letters containing consumers' names to family members of individuals receiving services. Following the breach, the entity implemented additional safeguarding and quality control procedures for mailings and updated its Breach Rule Notification policy.
- MOHHS OCRas victim2017-02-07
Missouri Department of Mental Health reported to HHS on 2017-02-07 a Hacking/IT Incident affecting 5,685 individuals. Business associate Burrell Behavioral Health reported that an unauthorized individual accessed an employee's email account containing ePHI. The employee also sent 13 personal emails to a third-party account. Compromised data included names, treatment information, SSNs, and financial information (~7,748 patients in the account). Breached information was located on Email. The BA conducted a forensic investigation, disabled global email internet access, and provided identity protection to affected individuals. OCR closed the case after confirming the BA agreement conformed to HIPAA requirements.