Back to the register
University of Oklahoma, Department of Obstetrics and Gynecology
ArchivedSubmitted 07/03/2015
- State
- OK
- Covered entity type
- Healthcare Provider
- Individuals affected
- 7,693
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unencrypted, password-protected laptop computer was stolen from a resident physician’s car. The laptop contained the electronic protected health information (ePHI) of approximately 7,693 individuals and included patients’ names, dates of birth, medical procedure dates, medications, lab results, admission and discharge dates, treating physicians’ names, and treatment plans. The covered entity (CE), University of Oklahoma, provided breach notification to HHS, affected individuals, and the media. It also offered identity protection services to affected individuals and posted substitute notice on its website. Following the breach, the CE retrained the resident physicians on its encryption policies and procedures and counseled and sanctioned the involved resident. As a result of OCR’s investigation, the CE developed a policy on encryption of laptops for all first-year residents. It also instituted a requirement for all first-year residents to disclose all laptops, tablets, and smartphones to be used for the CE’s business and to ensure they are encrypted by the CE’s representatives.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.