- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 538
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On April 28, 2018, a burglar stole a desktop computer from the office of the covered entity (CE), Denise M. Bowden, LAc, a licensed acupuncturist. The computer contained the protected health information (PHI) of 538 individuals, including demographic and clinical information. The CE notified the police, provided breach notification to HHS, affected individuals, and the media, and provided free credit monitoring. Following the breach, the CE strengthened password requirements for electronic systems and improved physical security. As a result of OCR’s investigation, the CE reset passcodes, implemented multi-factor authentication, installed a security camera, trained staff, and provided OCR with copies of policies and procedures for safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.