An unencrypted laptop computer was stolen from an administrative office. The laptop contained the protected health information (PHI) of approximately 1,618 patients (originally reported as 1,646). The types of PHI involved in the breach included the demographic and clinical information of pediatric cardiology patients, including names, medical record numbers, dates of service, diagnoses, and dates of birth. Following the breach, the covered entity (CE), Texas Children’s Hospital, and Baylor College of Medicine (which filed a separate breach report) jointly notified the affected individuals and the local media after a delay due to a law enforcement request. As a result of OCR’s investigation, the CE revised several information technology policies and modified physical safeguards.