UHS-Pruitt
Disclosed Nov 15, 201312 years ago1,300 affectedConfirmed
A manager's unencrypted laptop computer was stolen from a hotel parking lot which also included the employee's login and system password and the covered entity's (CE) long term care software application. The laptop contained 1,300 individuals' protected health information (PHI) and included names, social security numbers, addresses, dates of birth, bank account numbers, Medicare numbers, possible diagnoses, and patient locations. Following the breach, the CE changed the employee's password and performed an analysis to ensure no attempts had been made to access the system and long term care application using the prior account and password. The CE improved safeguards by encrypting electronic devices and employing devices that do not allow local storage. The CE has also re-trained employees. OCR has consolidated this review into a compliance review that involves the same corporate entity and another stolen unencrypted laptop. \ \ \
What is known
| People affected | 1,300 (as reported to HHS) |
|---|---|
| Disclosed | Nov 15, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): UHS-Pruitt (Healthcare Provider, GA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 15, 2013 | 1,300 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.