- State
- KS
- Covered entity type
- Healthcare Provider
- Individuals affected
- 52,076
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On December 30, 2015, a Valley Hope Association employee's work-issued laptop computer was stolen from her vehicle. The incident affected approximately 52,076 individuals. The protected health information (PHI) stored on the laptop included names, addresses, dates of birth, phone numbers, social security numbers, medical record numbers, treatment types and locations, as well as health insurance, financial, and medication information. The employee immediately reported the incident to the local police and the covered entity (CE). The CE conducted a forensic analysis and concluded that the system had not been accessed following the theft. Following the breach, the CE terminated the computer’s access to its computer network, reset the user’s password, and verified the laptop had no open connections to other electronic systems. The CE encrypted all devices containing PHI and implemented the use of software to mask social security numbers. The CE also developed an information security and privacy committee, updated its policies and procedures manual, and trained staff on its updated policies and procedures relating to password use and development, automatic time outs on electronic devices, malicious malware, and network access rights. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice on the home page of its website. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.