A St. Vincent Hospital and Health Care Center, Inc. laptop computer containing the protected health information (PHI of approximately 1,199 individuals was stolen from an employee’s home. The types of PHI involved in the breach included names, dates of birth, and in some instances, Social Security numbers, diagnoses, procedure types, physicians' names, home and work telephone numbers, and registration and medical record numbers. The CE provided breach notification to HHS, the media, and affected individuals. Following the breach, the CE encrypted its laptops, updated its policies and procedures related to safeguarding mobile devices, and implemented new procedures regarding physical security for laptops. OCR obtained documentation that the CE implemented the corrective actions noted above.