Skip to content

Bay Area Pain and Wellness Center

Disclosed Jun 14, 20179 years ago548 affectedConfirmed

Official notice

On May 8, 2017, the covered entity (CE), Bay Area Pain and Wellness Center, discovered that its Electromyography (EMG) machine was stolen from an employee's car. A laptop computer attached to the EMG contained the electronic protected health information (ePHI) of approximately 548 patients. The ePHI included patients' names and dates of birth. The laptop was password protected but not encrypted. The CE provided breach notification to HHS, affected individuals and the media, as well as providing substitute notification. In response to the breach, the CE retrained its employees on its Privacy and Security Rule policies, encrypted employees’ laptops, and updated its Security Rule policy to prohibit employees from leaving computer and computer bags in unattended public areas. OCR provided the CE with technical assistance regarding breach notification and the Security Rule risk analysis and risk management provisions.

What is known

People affected548 (as reported to HHS)
DisclosedJun 14, 2017
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 14, 2017548
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Bay Area Pain and Wellness Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.