HealthSouth Rehabilitation Hospital of Round Rock
Disclosed Dec 24, 201510 years ago1,359 affectedConfirmed
The CE reported that an employee’s unencrypted laptop computer was stolen from a vehicle. The CE determined that the laptop, which was password-protected, potentially included local copies of e-mails containing individuals’ names, addresses, dates of birth, social security numbers, phone numbers, insurance numbers, diagnoses, referral identification numbers or medical record numbers. The CE provided breach notification to HHS, affected individuals, and the media. At the time of the incident, the CE was in the process of acquiring another facility and encrypting laptops owned by the facility. In response to the breach, the CE took additional steps to locate and secure any other remaining laptops owned by the facility it was acquiring. Further, the CE implemented additional technical safeguards to prevent similar breaches and sanctioned the involved workforce member. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,359 (as reported to HHS) |
|---|---|
| Disclosed | Dec 24, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): HealthSouth Rehabilitation Hospital of Round Rock (Healthcare Provider, TX)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 24, 2015 | 1,359 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about HealthSouth Rehabilitation Hospital of Round Rock