- State
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,246
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Inspira Behavioral Care, Corp., the covered entity (CE), discovered that an unencrypted, password-protected computer containing protected health information (PHI) was stolen from its facility. The breach affected 4,246 individuals. The PHI involved included names, dates of birth, diagnoses, and treatment information. The covered entity provided breach notifications to HHS, all affected individuals, and the media. Following the breach, the covered entity reminded all workforce members to store all e-PHI on its secure cloud storage server. The covered entity sanctioned workforce members for failure to adhere to its policies and procedures regarding compliance with the HIPAA Security Rule. It encrypted all computers containing e-PHI, and installed physical security measures at its facility. In addition, it re-trained all staff members on the HIPAA Privacy and Security Rules. OCR obtained assurances that the covered entity implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.