- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,512
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 27, 2013, an unencrypted laptop computer containing the protected health information (PHI) of 3,512 individuals was stolen from a locked supply closet at the covered entity’s (CE) facility. The types of PHI involved in the breach likely included patients’ names, genders, addresses, telephone numbers, dates of birth, health insurance information, and medical records, including, appointment notes, diagnosis, treatments, surgery notes, lab test results, prescriptions, instructions, and other information relating to podiatric care. The CE provided breach notification to HHS, affected individuals, and the media, and also contacted the police. Following the breach, the CE conducted an enterprise-wide risk analysis, implemented a risk management plan, encrypted its workstations and devices, and improved physical safeguards. The CE also implemented several other administrative and technical safeguards to ensure its compliance with the Security Rule. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.