On February 5, 2018, an encrypted laptop computer belonging to a business associate (BA), The Management Group's IRIS Consultant, was stolen from her car along with a work bag that contained a notebook with the password to the laptop. The laptop may have contained the protected health information (PHI) of about 779 individuals’ participation in the IRIS program and services they receive, including demographic and financial information. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media and provided substitute notice on its website. It also offered 12 months identity theft protection. The CE demonstrated that at the time of the breach it had a BA agreement with The Management Group with provisions regarding the use, disclosure, and safeguarding of protected health information and advised OCR that it will review and revise the contract as appropriate upon renewal. Following the breach, the BA reported the theft to the police, disabled the laptop’s capability to connect to the network/system, and sanctioned the employee whose laptop was stolen due to her violation of established policies and HIPAA training. OCR obtained documented assuranc