Inspira Behavioral Care
Disclosed May 2, 20197 years ago4,246 affectedConfirmed
Inspira Behavioral Care, Corp., the covered entity (CE), discovered that an unencrypted, password-protected computer containing protected health information (PHI) was stolen from its facility. The breach affected 4,246 individuals. The PHI involved included names, dates of birth, diagnoses, and treatment information. The covered entity provided breach notifications to HHS, all affected individuals, and the media. Following the breach, the covered entity reminded all workforce members to store all e-PHI on its secure cloud storage server. The covered entity sanctioned workforce members for failure to adhere to its policies and procedures regarding compliance with the HIPAA Security Rule. It encrypted all computers containing e-PHI, and installed physical security measures at its facility. In addition, it re-trained all staff members on the HIPAA Privacy and Security Rules. OCR obtained assurances that the covered entity implemented the corrective actions noted above.
What is known
| People affected | 4,246 (as reported to HHS) |
|---|---|
| Disclosed | May 2, 2019 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Inspira Behavioral Care (Healthcare Provider, )ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 2, 2019 | 4,246 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.