Rape & Brooks Orthodontics
Disclosed Mar 28, 201115 years ago20,744 affectedConfirmed
On February 4, 2011, covered entity’s (CE) facility was broken into and a computer server, three desktop computers, and an external hard drive were stolen, affecting the demographic, clinical and financial information of approximately 20,744 individuals. The CE, Rape & Brooks Orthodontics, P.C., provided breach notification to HHS, affected individuals, and the media. As a result of this incident, the CE increased physical security by upgrading its alarm system, changing and installing additional locks, and storing its server in a locked data closet. The CE also improved technical safeguards by implementing double-layered password protection on its computers and encrypting data on external hard drives. OCR obtained and reviewed the CE’s relevant HIPAA policies and procedures.
What is known
| People affected | 20,744 (as reported to HHS) |
|---|---|
| Disclosed | Mar 28, 2011 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Rape & Brooks Orthodontics (Healthcare Provider, AL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 28, 2011 | 20,744 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.