Indiana Health Centers
Disclosed Sep 12, 20179 years ago1,697 affectedConfirmed
On August 19, 2017, a desktop computer and two laptop computers were stolen during a break-in at the covered entity's (CE) South Bend location, affecting 1,697 individuals. The protected health information (PHI) involved in the breach included clinical and demographic information. The CE provided breach notification to HHS, affected individuals, and the media. To resolve the issues raised in this matter, the CE encrypted laptop computers and hard drives and began a practice of enabling full disk encryption on all new devices before deploying them to the production network. Additionally, the CE implemented a Security Incident and Event Management System (SIEM) that monitors a large volume of electronic device logs and computer network traffic to identify and respond to potential security threats and implemented advanced physical security features at all its locations with additional plans for 2019. The CE sanctioned the case manager with a verbal warning and required her to review the Workstation Use Policy. OCR obtained documented assurances that the CE implemented these corrective action steps.
What is known
| People affected | 1,697 (as reported to HHS) |
|---|---|
| Disclosed | Sep 12, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Indiana Health Centers (Healthcare Provider, IN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 12, 2017 | 1,697 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.