DaVita, the covered entity (CE), reported that on September 6, 2013, an employee’s unencrypted laptop computer was stolen from a locked car. When the laptop was stolen, the CE believed that it was encrypted in accordance with its policy and did not contain any electronic protected health information (ePHI). Upon further investigation, the CE determined that the laptop was not encrypted and contained patient ePHI pertaining to 10,849 individuals, including diagnosis and insurance information, as well as the social security numbers of some patients. The CE provided breach notification to the affected individuals, the media, and HHS. Following the breach, the CE retrained the involved employee on physical security of laptops, retrained relevant IT personnel on standard encryption configuration processes, and issued a company-wide reminder about physical security requirements pertaining to mobile devices. It also ensured that its laptops are encrypted, revised its device management and monitoring policies and procedures and its acceptable use policy (to include “bring your own device” practices). Additionally, the CE revised its security incident response and crisis management plan and