- State
- GA
- Covered entity type
- Business Associate
- Individuals affected
- 1,103
- Business associate present
- Yes
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 11, 2012, an employee of LifeGas , a business associate (BA) of the covered entity (CE), American Home Patient Inc., lost or misplaced an unencrypted laptop computer containing the electronic protected health information (ePHI) of 1,103 of the CE’s clients across 13 states. The ePHI stored in the laptop included patients’ names, addresses, and an indicator showing that the patient received oxygen supplies. The CE determined that a thumb drive that was misplaced in the same incident did not contain PHI. The CE conducted an internal investigation, and provided breach notification to HHS and affected individuals. In addition, the CE negotiated a new agreement with the BA, including stringent provisions regarding the timeframes allowed for future breach notifications. OCR obtained assurances the CE completed the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.