Skip to content

Lucile Packard Childrens Hospital, Privacy Manager Breach

Disclosed Jun 13, 201313 years ago12,900 affectedConfirmed

Official notice

The covered entity (CE), Stanford School of Medicine (SOM) and Stanford Children's Hospital (SCH)(formerly Lucile Packard Children's Hospital), reported that on May 8, 2013, a workforce member’s laptop was stolen from a badge-access controlled area of the hospital. SCH employed the workforce member; however, SOM owned and managed the laptop. The laptop was password-protected, but not encrypted. The electronic protected health information (ePHI) of approximately 12,900 individuals may have been affected by this breach. The type of ePHI involved included clinical and demographic information. The CE reported the theft to law enforcement, notified the affected individuals, offered identity protection services at no cost to the affected individuals, established a toll-free call center to assist affected individuals with questions or concerns, and submitted notification to the media and HHS. Following the breach and OCR’s corresponding investigation, the CE sanctioned the workforce member for violating its HIPAA policies, ensured that SOM’s devices were encrypted and compliant with data security policies, and restricted SCH users’ ability to download attachments to unencrypted devices. T

What is known

People affected12,900 (as reported to HHS)
DisclosedJun 13, 2013
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 13, 201312,900
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Lucile Packard Childrens Hospital, Privacy Manager Breach

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.