Back to the register

Lucile Packard Childrens Hospital, Privacy Manager Breach

ArchivedSubmitted 06/13/2013
State
CA
Covered entity type
Healthcare Provider
Individuals affected
12,900
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Stanford School of Medicine (SOM) and Stanford Children's Hospital (SCH)(formerly Lucile Packard Children's Hospital), reported that on May 8, 2013, a workforce member’s laptop was stolen from a badge-access controlled area of the hospital. SCH employed the workforce member; however, SOM owned and managed the laptop. The laptop was password-protected, but not encrypted. The electronic protected health information (ePHI) of approximately 12,900 individuals may have been affected by this breach. The type of ePHI involved included clinical and demographic information. The CE reported the theft to law enforcement, notified the affected individuals, offered identity protection services at no cost to the affected individuals, established a toll-free call center to assist affected individuals with questions or concerns, and submitted notification to the media and HHS. Following the breach and OCR’s corresponding investigation, the CE sanctioned the workforce member for violating its HIPAA policies, ensured that SOM’s devices were encrypted and compliant with data security policies, and restricted SCH users’ ability to download attachments to unencrypted devices. The CE also initiated plans to implement an improved risk management process.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.