W. W. Grainger, Inc., (WWGI), the covered entity (CE), reported that an employee’s laptop containing the protected health information (PHI) of 1,594 individuals was stolen from his unlocked vehicle. The PHI involved included names, dates of birth, Social Security numbers, addresses, and other demographic information. WWGI notified HHS, affected individuals, the media, and provided substitute notice. As a result of OCR’s investigation, WWGI implemented additional administrative safeguards and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
People affected
57,992 (as reported by the organization)
Disclosed
Sep 18, 2017
Discovered
Aug 23, 2017
Happened
Sep 26, 2017
Attack
Lost or stolen device
Data exposed
Names, Social Security numbers, Government IDs, Payment cards, Health
2026-09-25 · sector: other to insurance · backfill source
2026-09-25 · data_types: ["names","ssn","government-id","payment-card"] to ["names","ssn","government-id","payment-card","health"] · backfill source
2026-09-25 · summary: empty to W. W. Grainger, Inc., (WWGI), the covered entity (CE), reported that an employee’s laptop containing the protected health information (PHI) of 1,594 individuals was stolen from his unlocked vehicle. The PHI involved included names, dates of · backfill source
2026-09-25 · data_types: ["names"] to ["names","ssn","government-id","payment-card"] · backfill source
2026-09-25 · data_types: [] to ["names"] · backfill source
2026-09-25 · records_basis: empty to organization · backfill source
2026-09-25 · records: empty to 57992 · backfill source
2026-09-25 · attack: unknown to lost-device · backfill source
2026-09-25 · disclosed: 2017-09-19 to 2017-09-18 · backfill source
2026-09-25 · discovered: empty to 2017-08-23 · backfill source
2026-09-25 · disclosed: 2018-04-20 to 2017-09-19 · backfill source