The covered entity (CE), United Seating and Mobility LLC dba Numotion, discovered a break-in at their Colorado Springs, Colorado location from where eight laptop computers, four mobile phones, one portable computer drive (a USB device), and a laptop bag with some documentation were stolen. The stolen items potentially compromised the protected health information (PHI) of approximately 3,578 individuals, including demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media and offered free credit monitoring to the affected individuals. Although most of the stolen devices were encrypted, the CE audited all its electronic devices and established a regular audit program to test full disk encryption verification, enterprise-wide, on a periodic basis and address any unverified devices. The CE reviewed physical security at the branch and began identifying appropriate improvements. The CE also began assessing an alternative two-factor, full disk encryption program for its electronic devices. OCR reviewed the CE's policies and procedures as they relate to this breach, they appear to be in compliance with the Privacy Rule.