- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,229
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
This case was consolidated into an investigation of Quarles & Brady, a business associate (BA) of CVS Health and the covered entity (CE), OptumRx. On March 16, 2016, a briefcase containing a Quarles & Brady workforce member’s laptop computer was stolen from the workforce member’s vehicle in Indianapolis. The laptop was password protected, but not encrypted, and contained the protected health information (PHI) of 7,261 individuals, in violation of the BA’s policy. The PHI included names, addresses, and medications. The CE provided breach notification to HHS, affected individuals, and the media. To resolve the issues raised in this matter, the BA disciplined the workforce member involved by issuing a formal reprimand, retrained the workforce member, and subjected the workforce member to a period of monitoring. The BA also encrypted all workforce laptops, sent emails to all workforce members reminding them that storing PHI on a computer hard drive violates its policy, and gave instructions on how to delete PHI from the hard drive. Additionally, the BA required all health law attorneys to attest to reviewing all information saved to their hard drives and removing any PHI and retrained all health law attorneys and staff on the importance of HIPAA compliance for the use of laptops. OCR obtained documented assurances from the BA that it implemented the corrective action steps described here.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.