- State
- IN
- Covered entity type
- Business Associate
- Individuals affected
- 7,242
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 28, 2016, an employee’s laptop computer was stolen from her car. The laptop may have contained the demographic and health insurance information of approximately 7,242 individuals. The employee reported the theft to local law enforcement, and the covered entity (CE), Gibson Insurance Agency, Inc., provided breach notification to HHS, affected individuals, and the media. Following the incident, the CE investigated the breach, sanctioned the employee involved, implemented policies regarding the use of portable workstations outside the office, and retrained employees. The CE improved safeguards by encrypting all computers, deploying a security management system to all mobile devices, mandating the use of complex passwords, and instituting automatic logoff. OCR reviewed the CE’s policies and procedures relating to the disclosure, breach, safeguarding of PHI, and sanctions and obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.