Surgical Care Affiliates
Disclosed May 16, 201610 years ago9,009 affectedConfirmed
Surgical Care Affiliates, the covered entity (“CE”), discovered that on March 17, 2016, a laptop computer had been stolen from an employee’s house. The laptop was password protected; however the employee’s username and password were with the laptop at the time of the theft. There was no patient information stored on the laptop, but Outlook emails were potentially cached on the hard drive. The CE opened an internal investigation and determined that 9,009 individuals may have had their names, addresses, dates of birth, social security numbers, treatment information, and health insurance information exposed as a result of this incident. The CE provided timely breach notification to HHS, to affected individuals, on its website, and to the media. In response to the breach, the CE retrained the employee involved to reinforce its existing HIPAA policies pertaining to the safeguarding of electronic devices and password management, and provided free credit monitoring to the affected individuals whose social security numbers may have been exposed. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 9,009 (as reported to HHS) |
|---|---|
| Disclosed | May 16, 2016 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Surgical Care Affiliates (Business Associate, AL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 16, 2016 | 9,009 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.