- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,119
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A laptop computer containing the protected health information (PHI) of approximately 3,260 individuals was stolen from an employee's locked vehicle between August 19, 2016, and Aug. 20, 2016. The types of PHI on the laptop included demographic and clinical information. The covered entity (CE), MGA Home Healthcare Colorado, Inc. (now under the common ownership of Zoe Holding Company Inc.), immediately filed a report with law enforcement. The CE provided breach notification to HHS, affected individuals, and the media and provided free credit monitoring. Following the breach, the CE implemented new technical safeguards, such as encrypting its laptop computers, strengthened password requirements, and improved physical security. The CE also created a new and updated Security Rule Risk Management Plan, performed a new Security Rule Risk Analysis, revised policies and procedures, sanctioned workforce members involved (including termination), took steps to mitigate harm, and trained or retrained workforce members. The CE consulted a forensics expert and contracted with a provider of cyber risk management and HIPAA compliance solutions regarding its risk analysis phases. OCR reviewed information regarding the CE’s staff training, a copy of its business associate agreement, and its policies and procedures for safeguarding electronic PHI and obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.