Back to the register

Gibson Insurance Agency, Inc.

ArchivedSubmitted 10/14/2016
State
IN
Covered entity type
Business Associate
Individuals affected
7,242
Business associate present
Yes
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On July 28, 2016, an employee’s laptop computer was stolen from her car. The laptop may have contained the demographic and health insurance information of approximately 7,242 individuals. The employee reported the theft to local law enforcement, and the covered entity (CE), Gibson Insurance Agency, Inc., provided breach notification to HHS, affected individuals, and the media. Following the incident, the CE investigated the breach, sanctioned the employee involved, implemented policies regarding the use of portable workstations outside the office, and retrained employees. The CE improved safeguards by encrypting all computers, deploying a security management system to all mobile devices, mandating the use of complex passwords, and instituting automatic logoff. OCR reviewed the CE’s policies and procedures relating to the disclosure, breach, safeguarding of PHI, and sanctions and obtained assurances that the CE implemented the corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.