A password-protected laptop, which was maintained by the covered entity (CE), Aultman Hospital, was stolen from an employee’s car, which contained the electronic protected health information (ePHI) of approximately 13,867 individuals, including patients’ names, dates of birth, telephone numbers, social security numbers, insurance identification, and health information related to home health services. The CE provided breach notification to HHS, affected individuals, and the media, posted notification of the breach on its website, and reported the theft to the local police department. The CE also offered one year of free credit monitoring services to affected individuals. Following the breach, the CE revised its HIPAA policies and procedures, enhanced encryption and updated software on its laptops, sanctioned employee(s) involved in the breach incident, and retrained its workforce on the revised policies and procedures. OCR obtained documentation evidencing that the CE implemented the corrective actions listed.