Colby DeHart
Disclosed Dec 19, 201312 years ago2,777 affectedConfirmed
On October 21, 2013, an unencrypted laptop computer belonging to a Tennova Cardiology business associate (BA) was stolen from a vehicle. The laptop contained the protected health information (PHI) of 2,777 individuals, and included patient names, dates of birth, dates of service, names of referring physicians, and health information about treatment and diagnostic procedures. The CE provided breach notification to HHS, affected individuals, and the media. In response to this breach, the covered entity (CE) conducted an encryption assessment of laptop computers with user system access to PHI and then encrypted all laptop computers. The CE reviewed its policies, retrained staff, and implemented an encryption policy. The CE also terminated the BA agreement and moved the work in-house. OCR obtained assurances that the CE implemented the corrective actions listed.
What is known
| People affected | 2,777 (as reported to HHS) |
|---|---|
| Disclosed | Dec 19, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Colby DeHart (Business Associate, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 19, 2013 | 2,777 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.