Oconee Physician Practices
Disclosed May 20, 201016 years ago653 affectedConfirmed
On May 9, 2010, the covered entity (CE), Oconee Physician Practices, discovered that a password-protected, unencrypted laptop computer used for EKG testing was missing from its facility. The loss potentially exposed the demographic and clinical information of 653 individuals. The CE provided breach notification to HHS, affected individuals, and the media. The CE improved safeguards by changing access codes and physical locks to the building and retrained its workforce on the importance of password protection and laptop security. The CE developed a plan to create a stronger policy for asset tracking, accountability, and activity monitoring and upgrade its procedures for password strength, automatic log-off capabilities, and limiting the number of sign-on attempts. The CE also developed a plan to encrypt laptops and other portable media containing electronic protected health information (ePHI). OCR reviewed the CE’s policies and procedures and supporting documents.
What is known
| People affected | 653 (as reported to HHS) |
|---|---|
| Disclosed | May 20, 2010 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Oconee Physician Practices (Healthcare Provider, SC)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 20, 2010 | 653 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.