Tower Imaging
Disclosed Apr 16, 20197 years ago810 affectedConfirmed
Tower Imaging, the covered entity (CE), discovered on February 19, 2019, that an unencrypted laptop computer was missing from its medical facility. The laptop contained the protected health information (PHI) of 810 individuals and was not recovered. The types of PHI included in the breach were patients’ names, dates of birth, and medical record numbers. The CE sent timely breach notification to HHS, the affected individuals, and the media. In response to the breach, the CE retrained staff members, updated policies and procedures, reviewed security codes for entering the facility, performed a risk analysis, and adopted a risk management plan. The CE also purchased a new laptop computer with an encrypted hard drive, password protected the computer, and locked the computer to a large rolling cart. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 810 (as reported to HHS) |
|---|---|
| Disclosed | Apr 16, 2019 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Tower Imaging (Healthcare Provider, FL)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 16, 2019 | 810 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.