Quarles & Brady
Disclosed Apr 19, 201610 years ago1,032 affectedConfirmed
Quarles & Brady is a business associate (BA) of the covered entities (CE), CVS Health and OptumRx. On March 16, 2016, a briefcase containing a Quarles & Brady workforce member’s laptop computer was stolen from the workforce member’s vehicle in Indianapolis. The laptop was password protected, but not encrypted, and contained the protected health information (PHI) of 7,261 individuals, in violation of the BA’s policy. The PHI included names, addresses, and medications. The CEs provided breach notification to affected individuals and the media. To resolve the issues raised in this matter, the BA disciplined the workforce member involved by issuing a formal reprimand, retrained the workforce member, and subjected the workforce member to a period of monitoring. The BA also encrypted all workforce laptops, sent emails to all workforce members reminding them that storing PHI on a computer hard drive violates its policy, and gave instructions on how to delete PHI from the hard drive. Additionally, the BA required all health law attorneys to attest to reviewing all information saved to their hard drives and removing any PHI and retrained all health law attorneys and staff on the importance
What is known
| People affected | 1,032 (as reported to HHS) |
|---|---|
| Disclosed | Apr 19, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Quarles & Brady (Business Associate, WI)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 19, 2016 | 1,032 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.