Skip to content

Stanford School of Medicine & LP Children Hosp, Privacy Manager Breach

Disclosed Jan 23, 201313 years ago56,500 affectedConfirmed

Official notice

The covered entity (CE), Stanford School of Medicine (SOM) and Stanford Children's Hospital (SCH)(formerly Lucile Packard Children's Hospital), reported that on January 9, 2013, a SOM workforce member's password-protected laptop was stolen from the workforce member’s vehicle. The CE reported that the electronic protected health information (ePHI) stored on the laptop was unencrypted. The ePHI of approximately 56,500 individuals may have been affected by this incident. The ePHI included demographic and clinical information related to SCH patient care and SOM research. Following this incident, the CE contacted law enforcement, notified the affected individuals, offered identity protection services to the affected individuals, established a call center to assist affected individuals with questions or concerns, and submitted notification to the media and HHS. The CE reported that there was no evidence of unauthorized access to the ePHI stored on the laptop. As a result of the breach and OCR’s corresponding investigation, the CE sanctioned the workforce member for violating HIPAA policies, and retrained workforce members on data security policies. SCH implemented enhanced administrative

What is known

People affected56,500 (as reported to HHS)
DisclosedJan 23, 2013
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 23, 201356,500
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Stanford School of Medicine & LP Children Hosp, Privacy Manager Breach

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.