Skip to content

W.W. Grainger

Disclosed Sep 18, 20179 years ago57,992 affectedConfirmed

Official notice

W. W. Grainger, Inc., (WWGI), the covered entity (CE), reported that an employee’s laptop containing the protected health information (PHI) of 1,594 individuals was stolen from his unlocked vehicle. The PHI involved included names, dates of birth, Social Security numbers, addresses, and other demographic information. WWGI notified HHS, affected individuals, the media, and provided substitute notice. As a result of OCR’s investigation, WWGI implemented additional administrative safeguards and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected57,992 (as reported by the organization)
DisclosedSep 18, 2017
DiscoveredAug 23, 2017
HappenedSep 26, 2017
AttackLost or stolen device
Data exposedNames, Social Security numbers, Government IDs, Payment cards, Health
SectorInsurance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: W.W. Graingeroag.ca.gov · Official notice
Washington Attorney General breach notice: W.W. Graingeratg.wa.gov · Official notice
Oregon DOJ breach notice: W.W. Graingerjustice.oregon.gov · Official notice
Indiana Attorney General 2017 data breach report: W.W.Graingerin.gov · Official notice
Maine Attorney General breach notice archive: W.W. Graingermaine.gov · Official notice
HHS OCR breach report (archive, resolved): W. W. Grainger (Health Plan, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Washington AGresidents of WASep 18, 2017725
HHS archivetotalSep 18, 20171,594
California AGresidents of CASep 19, 2017
Indiana AGresidents of INSep 19, 2017530
Maine AGresidents of MESep 19, 201754
Oregon DOJresidents of ORSep 20, 201757,992
California AGresidents of CAApr 20, 2018
Oregon DOJresidents of ORApr 20, 201817,902
Maine AGresidents of MEApr 20, 2018110

Other breaches at W.W. Grainger

BreachAffected
Disclosed Nov 18, 2015Nov 18, 201510 years agoUnknown
History of this record
  • 2026-09-25 · sector: other to insurance · backfill source
  • 2026-09-25 · data_types: ["names","ssn","government-id","payment-card"] to ["names","ssn","government-id","payment-card","health"] · backfill source
  • 2026-09-25 · summary: empty to W. W. Grainger, Inc., (WWGI), the covered entity (CE), reported that an employee’s laptop containing the protected health information (PHI) of 1,594 individuals was stolen from his unlocked vehicle. The PHI involved included names, dates of · backfill source
  • 2026-09-25 · data_types: ["names"] to ["names","ssn","government-id","payment-card"] · backfill source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 57992 · backfill source
  • 2026-09-25 · attack: unknown to lost-device · backfill source
  • 2026-09-25 · disclosed: 2017-09-19 to 2017-09-18 · backfill source
  • 2026-09-25 · discovered: empty to 2017-08-23 · backfill source
  • 2026-09-25 · disclosed: 2018-04-20 to 2017-09-19 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about W.W. Grainger

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.