Sunil Kakar, Psy.D
Disclosed Mar 29, 201313 years ago629 affectedConfirmed
On February 4, 2013, a personal laptop computer used to store medical reports and information about the covered entity’s (CE) clients was lost by, or stolen from, a provider formerly contracted by the CE. The computer's hard drive was wiped before it could be determined what information it contained, but the CE treated it as a breach affecting 629 individuals. The protected health information (PHI) involved in the breach may have included names, dates of birth, social security numbers, and clinical information, such as diagnoses or conditions. Following the breach, the CE updated contract language with business associates and contractors to include data security requirements and additional physical controls, as well as a self-assessment tool and monitoring plan. The CE added provisions to require contracted providers to provide proof of annual completion of a self-assessment tool and verification of encryption software use. OCR provided technical assistance on the Security Rule requirements and obtained assurances that breach notification was provided in accordance with the Breach Notification Rule requirements.
What is known
| People affected | 629 (as reported to HHS) |
|---|---|
| Disclosed | Mar 29, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Sunil Kakar, Psy.D (Business Associate, WA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 29, 2013 | 629 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.