The covered entity (CE), North East Medical Services, reported that on July 11, 2015, an unencrypted laptop computer used to store electronic protected health information (ePHI) was stolen from the trunk of a workforce member’s car. At the time of the breach, the laptop stored ePHI associated with 69,246 individuals. The ePHI included patients’ names, dates of birth, genders, contact information, payers/insurers, diagnoses, medications, treatment information, test results, appointment information, and, in some cases, social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE implemented encryption technology. It also updated relevant policies and procedures, including its policy on the use of encryption technology and strengthened password requirements for access to ePHI. Additionally, the CE sanctioned the workforce member responsible for the breach and provided additional training to all workforce members on its policies and procedures on uses and disclosures of PHI and encryption technology, In response to OCR’s investigation, the CE performed an updated Risk Analysis.
2026-09-25 · attack: unknown to lost-device · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 69246 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), North East Medical Services, reported that on July 11, 2015, an unencrypted laptop computer used to store electronic protected health information (ePHI) was stolen from the trunk of a workforce member’s car. At the · backfill source