Back to the register

The Johns Hopkins Hospital

ArchivedSubmitted 10/09/2015
State
MD
Covered entity type
Healthcare Provider
Individuals affected
571
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On October 10, 2015, the covered entity (CE), Johns Hopkins Hospital, reported that a physician’s unencrypted laptop computer storing the electronic protected health information (ePHI) of 571 individuals was stolen at an international airport with all of her belongings. The types of ePHI contained in the laptop included physicians' names, patients' names, medical record numbers, and clinical information. The CE provided breach notification to HHS, the media, affected individuals, and offered credit monitoring. The CE sanctioned the physician involved in accordance with the CE's HIPAA sanctions policy. The CE also circulated a broadcast reminder to its workforce members of their existing policy requiring all devices that contain or may contain PHI to be encrypted and password protected. OCR obtained assurances that any of the CE's portable devices that stores ePHI is required to use the CE's encryption program. Additionally, the CE submitted a copy of its most recent risk analysis and risk management program to OCR. They also provided OCR with information related to their new encryption program that would inform a user when he or she is out of compliance and send them to a website that would refer them to local IT administration. OCR obtained assurances that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.