Skip to content

HP Enterprise Services

Disclosed Dec 28, 201213 years ago1,090 affectedConfirmed

Official notice

An employee of a subcontractor for the covered entity's (CE) Business Associate (BA), responded to a telephone phishing attack and permitted a hacker to remotely access the laptop computer of the subcontractor. In violation of the subcontractor BA's policies, the laptop contained the protected health information (PHI) of 1,090 individuals, including names, dates of birth, diagnosis codes, and diagnosis code descriptions and some social security numbers and treatment descriptions. The CE, through its BA, provided breach notification to HHS, affected individuals, and the media, and provided substitute notice. The BA also offered a year of credit monitoring to those affected. In response to the incident, the subcontractor improved safeguards by initiating laptop audits to ensure PHI is not stored on them, re-trained employees, and applied employee sanctions by terminating the employee who failed to follow its policy. OCR obtained assurances that the corrective action listed above was completed. \ \

What is known

People affected1,090 (as reported to HHS)
DisclosedDec 28, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): HP Enterprise Services (Business Associate, KY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 28, 20121,090

Other breaches at HP Enterprise Services

BreachAffected
Disclosed Sep 21, 2016Sep 21, 201610 years agoLost or stolen device1,235
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about HP Enterprise Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.