On February 23, 2015, the covered entity (CE), Amedisys, Inc. discovered that 142 encrypted computers and laptops were unaccounted for, that were accessible to former employees who had left or been terminated by the CE between January 1, 2011 and December 31, 2014. The devices contained the electronic protected health information (ePHI) of approximately 6, 909 effected individuals. The types of ePHI involved in the incident included, names, dates of birth, addresses, social security numbers, other demographic information, diagnosis, lab results, medications, other treatment information, and claim information. The CE provided breach notification to HHS, individuals, and the media. As a result of this incident, the CE implemented an enhanced termination policy and device recovery process. The CE also implemented software that provides an offline device freeze policy, which completely freezes any device that does not connect to the CE’s network for a period of time. OCR provided technical assistance to the CE regarding conducting a risk analysis and the requirements to identify and assess the potential risks and vulnerabilities of ePHI. The CE hired a third party vendor to do a comple
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 6909 · backfill source
2026-09-25 · disclosed: 2015-03-02 to 2015-03-01 · backfill source
2026-09-25 · summary: empty to On February 23, 2015, the covered entity (CE), Amedisys, Inc. discovered that 142 encrypted computers and laptops were unaccounted for, that were accessible to former employees who had left or been terminated by the CE between January 1, 20 · backfill source