On May 1, 2012, an unencrypted laptop of a University of Kentucky Health Care employee with the protected health information (PHI) of approximately 4,488 individuals was stolen from a workforce member’s son, who borrowed the laptop without permission and knew the computer’s password. The PHI involved in the breach included medical record numbers, dates of visits, and chief complaints. The covered entity (CE) provided breach notification to HHS, the media, and affected individuals, set up a toll-free number for questions, and posted substitute notice on its website. The responsible workforce member was suspended pending an investigation and ultimately resigned. The CE created and revised its HIPAA policies and procedures, including its mobile device policy, and implemented additional security measures to address high and moderate risks identified in its risk analysis. Finally, the CE provided evidence of employee training and security reminders. OCR obtained assurances that the corrective actions listed above were completed.