Skip to content

Quarles & Brady

Disclosed Apr 19, 201610 years ago1,032 affectedConfirmed

Official notice

Quarles & Brady is a business associate (BA) of the covered entities (CE), CVS Health and OptumRx. On March 16, 2016, a briefcase containing a Quarles & Brady workforce member’s laptop computer was stolen from the workforce member’s vehicle in Indianapolis. The laptop was password protected, but not encrypted, and contained the protected health information (PHI) of 7,261 individuals, in violation of the BA’s policy. The PHI included names, addresses, and medications. The CEs provided breach notification to affected individuals and the media. To resolve the issues raised in this matter, the BA disciplined the workforce member involved by issuing a formal reprimand, retrained the workforce member, and subjected the workforce member to a period of monitoring. The BA also encrypted all workforce laptops, sent emails to all workforce members reminding them that storing PHI on a computer hard drive violates its policy, and gave instructions on how to delete PHI from the hard drive. Additionally, the BA required all health law attorneys to attest to reviewing all information saved to their hard drives and removing any PHI and retrained all health law attorneys and staff on the importance

What is known

People affected1,032 (as reported to HHS)
DisclosedApr 19, 2016
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Quarles & Brady (Business Associate, WI)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 19, 20161,032
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Quarles & Brady

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.