OneDigital/Digital Insurance
Disclosed Feb 15, 20197 years ago2,763 affectedConfirmed
On January 7, 2019, a business Associate (BA), OneDigital/Digital Insurance, LLC, discovered that an employee’s unencrypted laptop computer was stolen. The laptop contained the protected health information (PHI) of 4,045 individuals in the employee’s email account on the computer hard drive, including demographic, financial, clinical, and health plan information. The BA activated contingency protocols on the stolen laptop to prevent remote access to the BA’s network. From February 15, 2019, to April 8, 2019, the BA notified its affected clients (136 covered entities) of the breach and assisted with breach notification obligations. In response to the breach, the BA reset passwords, revised security policies, and sanctioned and retrained employees. Before the theft, the BA was in the process of encrypting laptops and anticipates that all laptops will be encrypted by the end of 2019. OCR obtained assurances that the BA implemented the corrective actions listed above and performed notification obligations.
What is known
| People affected | 2,763 (as reported to HHS) |
|---|---|
| Disclosed | Feb 15, 2019 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): OneDigital/Digital Insurance (Business Associate, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 15, 2019 | 2,763 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.