On May 25, 2014, a password-protected, unencrypted laptop computer containing the protected health information (PHI) of 38,906 patients was stolen from the covered entity’s (CE) administrative offices during a break-in. The PHI involved in the breach included patients’ names, social security numbers, driver license numbers, treating physician names, insurance policy numbers, patient account numbers, service dates, diagnosis/procedure information, payment card information, financial account information, and possibly addresses. The CE provided breach notification to HHS, the media, and affected individuals, and offered credit monitoring. The CE also contacted the local police department and conducted an internal investigation. Following the breach the CE revised its HIPAA policies and procedures and retrained its entire workforce on its policies and procedures. The CE also improved facility access safeguards and encrypted computers. OCR obtained assurances that the CE implemented the corrective actions listed above.
2026-09-25 · attack: unknown to lost-device · backfill source
2026-09-25 · data_types: ["names","ssn","health","addresses","names"] to ["names","ssn","health","addresses"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 38906 · backfill source
2026-09-25 · summary: empty to On May 25, 2014, a password-protected, unencrypted laptop computer containing the protected health information (PHI) of 38,906 patients was stolen from the covered entity’s (CE) administrative offices during a break-in. The PHI involved in · backfill source