- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,594
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Children’s Hospital of Los Angeles, reported a breach of 3,594 individuals’ electronic protected health information (ePHI) resulting from theft of an unencrypted laptop stored in a workforce member’s vehicle while parked in a public parking lot. The breach affected patients' demographic information (name, date of birth, medical record number, address) and/or clinical information. Following the breach and in response to OCR’s contact in this matter, the CE took corrective actions, including blocking the laptop from accessing the CE's internal computer network, reminding staff not to store laptops or other mobile devices in vehicles, ensuring encryption on each Apple operated laptop, and implementing new policies. The CE provided breach notification to HHS, affected individuals, and the media.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.