- State
- WV
- Covered entity type
- Healthcare Provider
- Individuals affected
- 43,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On December 29, 2017, the covered entity (CE), Coplin Health System, reported that a password-protect, unencrypted laptop computer issued to a part-time employee was stolen from his automobile. The employee notified law enforcement and the CE immediately notified its information technology (IT) department of the theft. Further inquiry determined that the employee did not store protected health information (PHI) on the laptop, but used it to access and use the CE’s online Electronic Health Record (EHR) system and email system. The CE could not eliminate the risk that the laptop could have contained some PHI saved by prior users. At the time of the theft, the CE had an encryption policy in place requiring all laptops issued to employees to be encrypted. The CE immediately cancelled the credentials issued to the employee that enabled him to access its IT systems, including the EHR system. The CE’s IT department monitored its’ IT systems for any signs of unauthorized access and is expected to do so indefinitely. The CE counseled the employee policies and procedures with regard to security for laptops. Following the breach, the CE ensured that every laptop in its inventory was either encrypted or removed from active service. The CE also began implementing a mobile device management solution that will allow it to remotely wipe any CHS-owned devices that might be lost or stolen in the future. OCR obtained copy of the CE’s current risk assessment, its breach notification to affected individuals, and copies of HIPAA policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.