The covered entity (CE), Hospital Auxilio Mutuo de Puerto Rico, Inc., reported that on November 9, 2010, an employee resigned his position and removed two computer hard drives and a laptop computer that contained electronic protected health information (ePHI), potentially affecting over 30,000 individuals. The CE initially reported that the breached ePHI included names, addresses, zip codes, dates of births, social security numbers, diagnostic conditions and other treatment information. During the investigation, the CE retrieved the hard drives and laptop and determined that the hard drives contained confidential financial information and business making decisions by the CE, and did not include the types of identifiers (e.g. patient names, Social Security numbers, home addresses, etc.) that could be used to re-identify an individual. Thus, the CE determined that the theft did not constitute a breach of ePHI. Further, the CE determined that the laptop was an information technology department laptop that only contained financial data and upper management e-mails. As of the result of OCR’s investigation, OCR has required the CE to conduct a risk analysis, implement a risk management p