An employee of Myriad Genetic Laboratories, Inc. (UT) emailed unsecured PHI to his personal email account for job-convenience purposes. The PHI of 643 individuals included names, dates of birth, addresses, physicians' names, genetic test results, test IDs, family and personal medical histories, and family pedigree information. The CE notified HHS and affected individuals, posted substitute notice, and offered one year of free identity theft protection. Post-breach, the CE revised email encryption procedures, retrained the employee, and received OCR technical assistance on Security Rule risk analysis. Submitted to HHS OCR on 2014-03-29.
Affected (this filing): 643