Foundations Recovery Network
Disclosed Jun 24, 201313 years ago5,690 affectedConfirmed
A password-word protected, unencrypted laptop was stolen from the covered entity’s (CE) employee’s car in her neighborhood. The laptop contained the protected health information (PHI) of 5,690 individuals and included patient names, dates of birth, addresses, telephone numbers, social security numbers, diagnoses, level of care, dates of service, and health insurance identifiers. The CE conducted an investigation and filed a police report. The CE provided breach notifications to HHS and affected individuals. Following the breach, the CE disabled the laptop’s access to its internal systems and changed the passwords. The employee was formally reprimanded and retrained. The CE hired experts to perform a risk assessment and gap analysis of its existing privacy and security practices, policies, and procedures and instituted a policy prohibiting workforce members from removing unencrypted company laptops from the premises. The CE retrained employees at all levels on its HIPAA policies and procedures and provided company-wide email reminders to all workforce members regarding privacy and security protections. The CE established roles to address compliance, including a compliance committee
What is known
| People affected | 5,690 (as reported to HHS) |
|---|---|
| Disclosed | Jun 24, 2013 |
| Happened | Jun 15, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Foundations Recovery Networkoag.ca.gov · Official notice | Official notice |
| Maine Attorney General breach notice archive: Foundations Recovery Networkmaine.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Foundations Recovery Network (Healthcare Provider, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jun 24, 2013 | |
| Maine AGresidents of ME | Aug 12, 2013 | 7 |
| HHS archivetotal | Aug 15, 2013 | 5,690 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 5690 · backfill source
- 2026-09-25 · summary: empty to A password-word protected, unencrypted laptop was stolen from the covered entity’s (CE) employee’s car in her neighborhood. The laptop contained the protected health information (PHI) of 5,690 individuals and included patient names, dates o · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.