Skip to content

Valley Community Healthcare

Disclosed Mar 6, 201511 years ago1,233 affectedConfirmed

Official notice

On February 24, 2015, the covered entity (CE), Valley Community Healthcare, discovered that a laptop computer connected to the EKG/ECG machine was missing, and it was never recovered. The password protected, unencrypted laptop contained the demographic information of 1,233 individuals The CE provided breach notification to HHS, affected individuals, and the media. As a result of OCR’s investigation, the CE evaluated the threats and vulnerabilities to its electronic protected health information. In addition, the CE implemented encryption pursuant to the Security Rule and increased the frequency of emails reminding employees to change their passwords. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected1,233 (as reported to HHS)
DisclosedMar 6, 2015
HappenedFeb 24, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 6, 20151,233
California AGresidents of CAMar 9, 2015
History of this record
  • 2026-09-25 · attack: unknown to lost-device · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 1233 · backfill source
  • 2026-09-25 · disclosed: 2015-03-09 to 2015-03-06 · backfill source
  • 2026-09-25 · summary: empty to On February 24, 2015, the covered entity (CE), Valley Community Healthcare, discovered that a laptop computer connected to the EKG/ECG machine was missing, and it was never recovered. The password protected, unencrypted laptop contained the · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Valley Community Healthcare

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.