A physician’s unencrypted personal laptop computer, which he used for business purposes, was stolen from his office on the campus of the covered entity (CE), Beth Israel Deaconess Medical Center. The laptop contained the PHI of approximately 3,900 individuals, including short summaries of medical information and the names and social security numbers of two individuals. After discovering the breach, the CE notified the police and hired an independent forensic firm. The CE provided breach notification to HHS, affected individuals, and the media. The CE also offered affected individuals one year of free credit monitoring and access to a dedicated call center to contact with questions regarding the incident. As a result of this incident, the CE retrained staff, enhanced its data security policy, and initiated an awareness campaign to educate and alert its workforce of security and privacy issues. The CE improved technical safeguards by encrypting or disabling all of its laptops. The CE counseled the physician whose laptop was stolen and assured that his replacement laptop was secured to the desk and encrypted. OCR’s investigation occurred simultaneously with the Massachusetts Attorney