An unsecured tablet computer was stolen from an employee’s vehicle on January 6, 2012. The protected health information (PHI) involved in the breach included names, addresses, dates of birth, treating physicians’ names and health screening results for 1,972 individuals. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. As a result of OCR’s investigation, OCR reviewed the CE’s HIPAA policies, documentation of workforce training related to safeguarding mobile devices, and its risk analysis related to mobile devices. Following the incident, the CE implemented additional technical safeguards, including encryption solutions, as part of its mobile device management program.