- State
- GA
- Covered entity type
- Business Associate
- Individuals affected
- 2,763
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 7, 2019, a business Associate (BA), OneDigital/Digital Insurance, LLC, discovered that an employee’s unencrypted laptop computer was stolen. The laptop contained the protected health information (PHI) of 4,045 individuals in the employee’s email account on the computer hard drive, including demographic, financial, clinical, and health plan information. The BA activated contingency protocols on the stolen laptop to prevent remote access to the BA’s network. From February 15, 2019, to April 8, 2019, the BA notified its affected clients (136 covered entities) of the breach and assisted with breach notification obligations. In response to the breach, the BA reset passwords, revised security policies, and sanctioned and retrained employees. Before the theft, the BA was in the process of encrypting laptops and anticipates that all laptops will be encrypted by the end of 2019. OCR obtained assurances that the BA implemented the corrective actions listed above and performed notification obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.