Back to the register

Seton Healthcare Family

ArchivedSubmitted 10/23/2013
State
TX
Covered entity type
Healthcare Provider
Individuals affected
5,500
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR opened an investigation of the covered entity (CE), Seton Healthcare Family after it reported that on October 4, 2013, an unencrypted laptop computer that contained the electronic protected health information (ePHI) of 5,500 patients was stolen from a clinic. The ePHI included patients' names, medical record numbers, account numbers, social security numbers, dates of birth, diagnoses, immunizations, and insurance information. The CE notified HHS, affected individuals, and the media in accordance with the Breach Notification Rule and provided free credit monitoring services for one year. The CE took a number of corrective actions to prevent future breaches. It implemented a full disk encryption policy to be applied prior to deployment of new computers, updated internal processes, and retrained staff on its updated processes. The CE also sanctioned and re-trained the workforce member involved in the breach, and confirmed the same was applied to the Dell IT technician involved with system upgrades, including encryption. OCR obtained assurances that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.