Skip to content

Self Regional Healthcare

Disclosed Jul 22, 201412 years ago38,906 affectedConfirmed

Official notice

On May 25, 2014, a password-protected, unencrypted laptop computer containing the protected health information (PHI) of 38,906 patients was stolen from the covered entity’s (CE) administrative offices during a break-in. The PHI involved in the breach included patients’ names, social security numbers, driver license numbers, treating physician names, insurance policy numbers, patient account numbers, service dates, diagnosis/procedure information, payment card information, financial account information, and possibly addresses. The CE provided breach notification to HHS, the media, and affected individuals, and offered credit monitoring. The CE also contacted the local police department and conducted an internal investigation. Following the breach the CE revised its HIPAA policies and procedures and retrained its entire workforce on its policies and procedures. The CE also improved facility access safeguards and encrypted computers. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected38,906 (as reported to HHS)
DisclosedJul 22, 2014
HappenedMay 25, 2014
AttackLost or stolen device
Data exposedNames, Social Security numbers, Health, Addresses
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Maine AGresidents of MEJul 22, 20143
HHS archivetotalJul 25, 201438,906

Other breaches at Self Regional Healthcare

BreachAffected
Disclosed Jul 24, 2024Jul 24, 20242 years agoHacking27K
Disclosed Oct 21, 2019Oct 21, 20196 years agoHacking52K
History of this record
  • 2026-09-25 · attack: unknown to lost-device · backfill source
  • 2026-09-25 · data_types: ["names","ssn","health","addresses","names"] to ["names","ssn","health","addresses"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 38906 · backfill source
  • 2026-09-25 · summary: empty to On May 25, 2014, a password-protected, unencrypted laptop computer containing the protected health information (PHI) of 38,906 patients was stolen from the covered entity’s (CE) administrative offices during a break-in. The PHI involved in · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Maine AG), confirmed by Maine AG. Record counts are as reported. Not legal advice.

Everything about Self Regional Healthcare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.