- State
- IN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,697
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 19, 2017, a desktop computer and two laptop computers were stolen during a break-in at the covered entity's (CE) South Bend location, affecting 1,697 individuals. The protected health information (PHI) involved in the breach included clinical and demographic information. The CE provided breach notification to HHS, affected individuals, and the media. To resolve the issues raised in this matter, the CE encrypted laptop computers and hard drives and began a practice of enabling full disk encryption on all new devices before deploying them to the production network. Additionally, the CE implemented a Security Incident and Event Management System (SIEM) that monitors a large volume of electronic device logs and computer network traffic to identify and respond to potential security threats and implemented advanced physical security features at all its locations with additional plans for 2019. The CE sanctioned the case manager with a verbal warning and required her to review the Workstation Use Policy. OCR obtained documented assurances that the CE implemented these corrective action steps.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.