An employee of the covered entity (CE), Brigham & Women’s Hospital, had an encrypted laptop and cell phone stolen during an armed robbery and was forced to disclose password and encryption keys during the robbery. The devices contained the protected health information PHI) of 999 individuals. The types of PHI involved in the breach included names, medical records numbers, age, and diagnostic information. In response to OCR’s investigation, the CE initiated a new enterprise wide risk analysis.