- State
- PA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 860
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
In August 2014, an Assistant U.S. Attorney contacted the CE, Kirkbride Center, to advise that an individual was arrested in Florida and would be tried for identity theft. This individual had hard copies of the CE’s daily census reports containing patients’ names, dates of birth, and some social security numbers, affecting approximately 869 individuals. The arrestee was not known to have direct ties to the CE’s facility and was convicted of identity theft. The CE’s internal investigation determined that a rogue employee stole the reports and the CE continued the investigation in hopes of determining which employee was responsible for the theft. The CE provided breach notification HHS, the media, and affected individuals, and posted notice on its website. The CE also offered affected individuals one year of free identity theft protection. Due to OCR’s investigation, the CE began using a new billing software system, which allows it to revise the daily census report to exclude patients’ dates of birth and social security numbers. Furthermore, the CE revised the report distribution process to limit the distribution of the report to specific unit personnel.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.