Skip to content

Stanford Hospital & Clinics and School of Medicine, Privacy Manager Breach

Disclosed Aug 3, 201214 years ago2,300 affectedConfirmed

Official notice

The covered entity (CE), Stanford Health Care (SHC)(formerly Stanford Hospital and Clinics), and Stanford School of Medicine (SOM), reported that on July 15 or 16, 2012, a password-protected computer was stolen from a locked SOM workforce member's office. The electronic protected health information (ePHI) of approximately 2,641 individuals may have been affected by this incident. The ePHI involved in the breach included clinical and demographic information related to SHC patient care and SOM research. The CE reported that there was no evidence to indicate that ePHI had been inappropriately accessed. The CE contacted law enforcement, notified the affected individuals, offered identity protection services at no cost to the affected individuals, established a toll-free call center to assist affected individuals with questions or concerns, and notification the media and HHS. As a result of the breach and OCR’s corresponding investigation, the CE implemented additional physical safeguards, audited SCH desktops and laptops to ensure encryption, issued security awareness reminders to workforce, and initiated plans to implement an improved risk management process.

What is known

People affected2,300 (as reported to HHS)
DisclosedAug 3, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalAug 3, 20122,300
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Stanford Hospital & Clinics and School of Medicine, Privacy Manager Breach

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.