Soundpath Health
Disclosed Dec 23, 201114 years ago7,581 affectedConfirmed
A laptop containing the protected health information (PHI) of approximately 7,581 clients was stolen out a workforce member's vehicle and subsequently used to access the covered entity's (CE) company server. The laptop contained clients' demographic information. After the incident, the CE performed a risk analysis of the specific breach occurrence. The CE provided OCR with a copy of its risk analysis, as well as its privacy, breach notification, and security policies and procedures. Following OCR's investigation, the CE performed a broader security risk assessment and encrypted all mobile media. The CE also developed and provided computer security training to its staff members.
What is known
| People affected | 7,581 (as reported to HHS) |
|---|---|
| Disclosed | Dec 23, 2011 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Insurance · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Soundpath Health (Health Plan, WA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 23, 2011 | 7,581 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.