- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,690
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A password-word protected, unencrypted laptop was stolen from the covered entity’s (CE) employee’s car in her neighborhood. The laptop contained the protected health information (PHI) of 5,690 individuals and included patient names, dates of birth, addresses, telephone numbers, social security numbers, diagnoses, level of care, dates of service, and health insurance identifiers. The CE conducted an investigation and filed a police report. The CE provided breach notifications to HHS and affected individuals. Following the breach, the CE disabled the laptop’s access to its internal systems and changed the passwords. The employee was formally reprimanded and retrained. The CE hired experts to perform a risk assessment and gap analysis of its existing privacy and security practices, policies, and procedures and instituted a policy prohibiting workforce members from removing unencrypted company laptops from the premises. The CE retrained employees at all levels on its HIPAA policies and procedures and provided company-wide email reminders to all workforce members regarding privacy and security protections. The CE established roles to address compliance, including a compliance committee and a compliance director. OCR obtained assurances that the corrective actions listed above were taken. Two of the three individuals involved in the theft of the laptop were arrested.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.