- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Dr. Brian Halevie-Goldman, the covered entity (CE), reported a breach that occurred when two laptop computers, a laptop bag containing super-bills and receipts, disability paperwork, copies of prescriptions, lists of symptoms identified by patients, miscellaneous papers to be shredded, and blank controlled and non-controlled prescription pads, and a smart phone were stolen from the physician’s locked vehicle. The types of protected health information (PHI) involved in the breach included the full names, addresses, internal medical record numbers, credit card information, diagnosis/conditions, lab results, medications, and clinical note files for approximately 2,000 individuals. The CE provided breach notification to affected individuals, the media, and HHS, and also provided substitute notice. Following the breach, the CE immediately reported the theft to local law enforcement. In addition, the CE engaged an independent firm to implement additional protective measures. As a result of the breach, the CE purchased new office equipment and security software, created and implemented a log for equipment that travels between offices, encrypted electronic devices that store PHI, and revised policies and procedures to safeguard PHI. The CE also trained workforce members on its revised policies. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.