This case was consolidated into an investigation of Quarles & Brady, a business associate (BA) of CVS Health and the covered entity (CE), OptumRx. On March 16, 2016, a briefcase containing a Quarles & Brady workforce member’s laptop computer was stolen from the workforce member’s vehicle in Indianapolis. The laptop was password protected, but not encrypted, and contained the protected health information (PHI) of 7,261 individuals, in violation of the BA’s policy. The PHI included names, addresses, and medications. The CE provided breach notification to HHS, affected individuals, and the media. To resolve the issues raised in this matter, the BA disciplined the workforce member involved by issuing a formal reprimand, retrained the workforce member, and subjected the workforce member to a period of monitoring. The BA also encrypted all workforce laptops, sent emails to all workforce members reminding them that storing PHI on a computer hard drive violates its policy, and gave instructions on how to delete PHI from the hard drive. Additionally, the BA required all health law attorneys to attest to reviewing all information saved to their hard drives and removing any PHI and retrained
2026-09-25 · sector: other to health · backfill source
2026-09-25 · attack: unknown to lost-device · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 6229 · backfill source
2026-09-25 · summary: empty to This case was consolidated into an investigation of Quarles & Brady, a business associate (BA) of CVS Health and the covered entity (CE), OptumRx. On March 16, 2016, a briefcase containing a Quarles & Brady workforce member’s laptop compute · backfill source