Henry Ford Health System, the covered entity (CE) reported breaches that occurred on September 24, 2010, January 31, 2011, August 5, 2011, and October 23, 2014. OCR consolidated the breaches into one investigation because the breaches contained similar issues and each breach involved employees who failed to follow the CE’s policies or procedures. The September 24, 2010, breach affected 3,700 individuals and occurred when a laptop computer was stolen from an office left unlocked by an employee for approximately four hours while the employee was attending a meeting. The January 31, 2011, breach affected 2,777 individuals and occurred when an employee lost a personal portable electronic device (a “flash” drive) containing protected health information (PHI). The August 5, 2011, breach affected 520 individuals and occurred when an unencrypted desktop computer was stolen from a lab with secure access for workforce members. The desktop computer had been purchased directly by the department instead of through the CE’s established computer purchase procedures. The October 23, 2014, breach affected 2,336 individuals and occurred when a physician lost a flash drive. The physician failed to ad