Horizon Health Care Services, the covered entity (CE), reported that two unencrypted laptop computers were stolen from its Newark, NJ headquarters, affecting approximately 839,711 individuals. The types of protected health information (PHI) involved in the breach included names, dates of birth, insurance identification numbers, and in some instances social security numbers and/or clinical information. The CE provided breach notifications to HHS, affected individuals and the media. During the course of the investigation, the CE conducted a comprehensive inventory of all its computers containing PHI to ensure that they were fully encrypted, enhanced configuration settings on workstations to encrypt email containing electronic PHI, and disabled features on all devices that permitted exporting of data to removable storage media. It also implemented new procedures for information technology purchasing, decision-making and management, improved facility access controls, and retrained its workforce. OCR obtained assurances that the CE implemented the corrective actions noted above.