- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,182
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 17, 2013, two unencrypted laptop computers were stolen from the covered entity's facility in San Jose, California. One of the laptops reportedly contained the electronic protected health information (ePHI) of approximately 2,182 individuals. In particular, the ePHI was included full names, home addresses, telephone numbers, date of birth information, and medical records. The CE provided breach notification to HHS, affected individuals, and the media and established a website to assist potentially affected individuals. The CE implemented measures to improve physical security and safeguard the ePHI it maintains. OCR provided substantive technical assistance and identified corrective actions that the CE must complete to comply with the Security Rule, which includes the following: conduct and monitor a comprehensive, enterprise-wide risk analysis as well as administer measures that support the results of that analysis, such as articulating policies and procedures and maintaining current business associated agreements.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.