- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 596
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unencrypted laptop computer containing the electronic protected health information (ePHI) of approximately 596 individuals was stolen from the covered entity's (CE), UT Physicians, facility. The laptop was stored in a locked closet, in an area secured by a key card. The laptop had been attached to an electromyography (EMG) nerve device and had been inventoried as a medical device. The ePHI included patients' names, dates of birth, and medical record numbers along with the values from the EMG machine. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE replaced the stolen laptop with an encrypted laptop and improved physical safeguards for the new laptop. Additionally, it inventoried and assessed devices and equipment containing ePHI and brought them into compliance with the CE’s policies, including encryption requirements. OCR obtained a copy of the CE's current risk analysis and risk management plan with evidence of implementation for security measures, including evidence of security measures to reduce the risk of computer theft.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.