Stronghold Counseling Services
Disclosed Feb 21, 201313 years ago8,500 affectedConfirmed
OCR opened an investigation of the covered entity (CE), Stronghold Counseling Services, after it reported that a desktop computer was missing from its facility. The computer contained protected health information (PHI) on appointments, client insurance, payments, and demographics, including social security numbers, as well as some client letters and reports. The breach affected 8,500 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE revised its procedures for encryption and implemented a risk analysis/risk management process. OCR provided technical assistance to the CE regarding the risk analysis and risk management requirements of the Security Rule and the requirements of the Breach Notification Rule.
What is known
| People affected | 8,500 (as reported to HHS) |
|---|---|
| Disclosed | Feb 21, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Stronghold Counseling Services (Healthcare Provider, SD)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 21, 2013 | 8,500 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.