University of Oklahoma, Department of Obstetrics and Gynecology
Disclosed Jul 3, 201511 years ago7,693 affectedConfirmed
An unencrypted, password-protected laptop computer was stolen from a resident physician’s car. The laptop contained the electronic protected health information (ePHI) of approximately 7,693 individuals and included patients’ names, dates of birth, medical procedure dates, medications, lab results, admission and discharge dates, treating physicians’ names, and treatment plans. The covered entity (CE), University of Oklahoma, provided breach notification to HHS, affected individuals, and the media. It also offered identity protection services to affected individuals and posted substitute notice on its website. Following the breach, the CE retrained the resident physicians on its encryption policies and procedures and counseled and sanctioned the involved resident. As a result of OCR’s investigation, the CE developed a policy on encryption of laptops for all first-year residents. It also instituted a requirement for all first-year residents to disclose all laptops, tablets, and smartphones to be used for the CE’s business and to ensure they are encrypted by the CE’s representatives.
What is known
| People affected | 7,693 (as reported to HHS) |
|---|---|
| Disclosed | Jul 3, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): University of Oklahoma, Department of Obstetrics and Gynecology (Healthcare Provider, OK)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 3, 2015 | 7,693 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about University of Oklahoma, Department of Obstetrics and Gynecology