- State
- NY
- Covered entity type
- Health Plan
- Individuals affected
- 2,772
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Someone stole a bag from an employee of a business associate (BA), Premier Home Care Services, Inc., that contained a laptop computer and smartphone. The laptop and smartphone contained the electronic protected health information (ePHI) of 2,772 of the covered entity's (CE) members, including demographic, clinical and health claims information. The CE provided breach notification to HHS, the media, its health plan clients, and the affected individuals (including the offer of free credit monitoring at no cost to the affected individuals), and posted notice on its website. Following the breach, the CE contacted law enforcement, conducted a forensic investigation, and sanctioned its BA, including the suspension of the BA's services for six months until it demonstrated it had substantially remediated risk areas. In addition, the BA entered into a Security Assessment and Remediation Plan which required it to implement new and/or updated policies and procedures related to IT security. OCR obtained assurances that the BA implemented the corrective actions listed. Additionally, the BA is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrievable exact copies of ePHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.