Back to the register

Loi Luu

ArchivedSubmitted 11/14/2014
State
CA
Covered entity type
Healthcare Provider
Individuals affected
13,177
Business associate present
No
Type of breach
Theft
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR investigated the covered entity (CE), Loi Luu, M.D., after the CE reported a breach of 13,177 individuals’ protected health information (PHI) and electronic PHI due to lost or stolen computer equipment and compromised lab results on, or around September 17, 2014. The breach affected patients’ names, addresses, phone numbers, dates of birth, social security numbers, medical insurance information and/or blood test results. The CE reported the incident to local law enforcement. In response to OCR’s contact in this matter, the CE ensured the proper breach notifications were provided, took steps to prevent the risk of future physical theft incidents at its office (such as by adding locks, cameras, and alarms), increased its technical controls of ePHI (such as utilizing encrypted software and conducting risk assessments), adopted HIPAA policies and procedures, and engaged in HIPAA training. The CE provided documentation of these corrective steps to OCR.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.