Blount Memorial Hospital
Disclosed Oct 17, 201213 years ago27,799 affectedConfirmed
The covered entity (CE), Blount Memorial Hospital, reported that a laptop computer containing the electronic protected health information (ePHI) of 27,799 individuals was stolen from a workforce member's home. The ePHI involved in the breach included demographic and other financial information. The CE provided breach notification to affected individuals, HHS, and the media. Following the breach, the CE reviewed its privacy and security policies and procedures, encrypted all of its laptops, and improved its HIPAA training. As a result of OCR's investigation, OCR provided technical assistance regarding the CE's security incident procedures and risk management plan. OCR also reviewed the CE's HIPAA policies and procedures that were created or revised in response to the breach. \ \ \
What is known
| People affected | 27,799 (as reported to HHS) |
|---|---|
| Disclosed | Oct 17, 2012 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Blount Memorial Hospital (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 17, 2012 | 27,799 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.