Valley Community Healthcare
Disclosed Mar 6, 201511 years ago1,233 affectedConfirmed
On February 24, 2015, the covered entity (CE), Valley Community Healthcare, discovered that a laptop computer connected to the EKG/ECG machine was missing, and it was never recovered. The password protected, unencrypted laptop contained the demographic information of 1,233 individuals The CE provided breach notification to HHS, affected individuals, and the media. As a result of OCR’s investigation, the CE evaluated the threats and vulnerabilities to its electronic protected health information. In addition, the CE implemented encryption pursuant to the Security Rule and increased the frequency of emails reminding employees to change their passwords. OCR obtained assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 1,233 (as reported to HHS) |
|---|---|
| Disclosed | Mar 6, 2015 |
| Happened | Feb 24, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Valley Community Healthcareoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Valley COmmunity Healthcare (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 6, 2015 | 1,233 |
| California AGresidents of CA | Mar 9, 2015 |
History of this record
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 1233 · backfill source
- 2026-09-25 · disclosed: 2015-03-09 to 2015-03-06 · backfill source
- 2026-09-25 · summary: empty to On February 24, 2015, the covered entity (CE), Valley Community Healthcare, discovered that a laptop computer connected to the EKG/ECG machine was missing, and it was never recovered. The password protected, unencrypted laptop contained the · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.