The covered entity (CE), the New York State Office of Mental Health, reported a breach when a workforce member lost her password-protected, but unencrypted, laptop computer in a New York City taxicab. The CE reported the laptop contained the protected health information of 563 participants in certain research studies at the CE’s Nathan S. Kline Institute for Psychiatric Research (NKI). The PHI consisted of names, phone numbers, ages or birthdates, and in some cases, coded diagnostic information, data obtained from assessments/tests and/or an informational note. The CE notified HHS, the media, and the affected individuals (including the offer of one year of identity protection services at no cost). Following the breach, the CE replaced all devices found to be out of compliance with current encryption standards, and implemented a network access control device to guarantee that unencrypted devices, and devices sourced from outside of the CE will no longer work on the NKI network. The CE also required investigators to submit more detailed data security plans to the Institutional Review Board, and restricted NKI researchers from downloading data from a specific research database without