Hospice Care Plus
Disclosed May 6, 20197 years ago2,033 affectedConfirmed
The covered entity (CE), Hospice Care Plus, Inc., reported that an employee left a company laptop containing the electronic protected health information (ePHI) of 2,033 individuals at a previous home. The ePHI involved included names, addresses, birthdates, diagnoses, medications prescribed, clinical information, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE sanctioned management and the employee. The CE also implemented additional technical and security safeguards and retrained its staff. OCR obtained assurances that the CE implemented the aforementioned corrective actions.
What is known
| People affected | 2,033 (as reported to HHS) |
|---|---|
| Disclosed | May 6, 2019 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Hospice Care Plus (Healthcare Provider, KY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 6, 2019 | 2,033 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.