- State
- AR
- Covered entity type
- Business Associate
- Individuals affected
- 1,911
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A break-in and burglary took place at the Office of Health Resources (HRA), a business associate (BA) of the covered entity (CE), the Arkansas Department of Humans Services (DHS). Two laptop computers which contained client files and the protected health information (PHI) of approximately 1,911 individuals were stolen. Following the breach, the CE improved physical safeguards, retrained workforce members, revised its HIPAA training for all employees on incident reporting procedures, and revised the Arkansas Business Associate Agreement (BAA) provisions on reporting breach incidents. Additionally, OCR’s investigation resulted in the CE’s development of a plan to survey its BAAs to assess HIPAA compliance and conduct on-site inspections.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.