Lewis J. Sims, DPM
Disclosed Feb 12, 201412 years ago6,475 affectedConfirmed
Three laptop computers belonging to the covered entity (CE), Sims & Podiatry Associates’, were stolen from its office. The laptops were unencrypted and contained electronic protected health information (ePHI) that included 6,474 patients’ addresses, zip codes, dates of birth and vascular test results. The CE provided breach notification to HHS, affected individuals, and the media. As a result of OCR’s investigation, the CE installed new locks on all its doors and an alarm security system with central station monitoring. The CE also purchased replacement laptops and a new server. Additionally, the CE secured all laptops with cable locks and implemented full disk encryption along with antivirus and anti-malware software. Further, the CE implemented real-time offsite backup of all its ePHI. OCR specified its expectation that the CE conduct an on-going risk analysis, implement an on-going risk management plan, conduct periodic vulnerability scans and penetration tests, implement audit controls and perform information system activity review. Further, OCR expects the CE to upgrade encryption for the Poughkeepsie office and ensure that portable hard drives are stored in a secured location
What is known
| People affected | 6,475 (as reported to HHS) |
|---|---|
| Disclosed | Feb 12, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Lewis J. Sims, DPM (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 12, 2014 | 6,475 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.