- State
- WI
- Covered entity type
- Health Plan
- Individuals affected
- 779
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 5, 2018, an encrypted laptop computer belonging to a business associate (BA), The Management Group's IRIS Consultant, was stolen from her car along with a work bag that contained a notebook with the password to the laptop. The laptop may have contained the protected health information (PHI) of about 779 individuals’ participation in the IRIS program and services they receive, including demographic and financial information. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media and provided substitute notice on its website. It also offered 12 months identity theft protection. The CE demonstrated that at the time of the breach it had a BA agreement with The Management Group with provisions regarding the use, disclosure, and safeguarding of protected health information and advised OCR that it will review and revise the contract as appropriate upon renewal. Following the breach, the BA reported the theft to the police, disabled the laptop’s capability to connect to the network/system, and sanctioned the employee whose laptop was stolen due to her violation of established policies and HIPAA training. OCR obtained documented assurances that the CE and BA, respectively, implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.