Coplin Health Systems
Disclosed Dec 29, 20178 years ago43,000 affectedConfirmed
On December 29, 2017, the covered entity (CE), Coplin Health System, reported that a password-protect, unencrypted laptop computer issued to a part-time employee was stolen from his automobile. The employee notified law enforcement and the CE immediately notified its information technology (IT) department of the theft. Further inquiry determined that the employee did not store protected health information (PHI) on the laptop, but used it to access and use the CE’s online Electronic Health Record (EHR) system and email system. The CE could not eliminate the risk that the laptop could have contained some PHI saved by prior users. At the time of the theft, the CE had an encryption policy in place requiring all laptops issued to employees to be encrypted. The CE immediately cancelled the credentials issued to the employee that enabled him to access its IT systems, including the EHR system. The CE’s IT department monitored its’ IT systems for any signs of unauthorized access and is expected to do so indefinitely. The CE counseled the employee policies and procedures with regard to security for laptops. Following the breach, the CE ensured that every laptop in its inventory was either en
What is known
| People affected | 43,000 (as reported to HHS) |
|---|---|
| Disclosed | Dec 29, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Coplin Health Systems (Healthcare Provider, WV)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 29, 2017 | 43,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.