Back to the register
Stanford School of Medicine & LP Children Hosp, Privacy Manager Breach
ArchivedSubmitted 01/23/2013
- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 56,500
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Stanford School of Medicine (SOM) and Stanford Children's Hospital (SCH)(formerly Lucile Packard Children's Hospital), reported that on January 9, 2013, a SOM workforce member's password-protected laptop was stolen from the workforce member’s vehicle. The CE reported that the electronic protected health information (ePHI) stored on the laptop was unencrypted. The ePHI of approximately 56,500 individuals may have been affected by this incident. The ePHI included demographic and clinical information related to SCH patient care and SOM research. Following this incident, the CE contacted law enforcement, notified the affected individuals, offered identity protection services to the affected individuals, established a call center to assist affected individuals with questions or concerns, and submitted notification to the media and HHS. The CE reported that there was no evidence of unauthorized access to the ePHI stored on the laptop. As a result of the breach and OCR’s corresponding investigation, the CE sanctioned the workforce member for violating HIPAA policies, and retrained workforce members on data security policies. SCH implemented enhanced administrative and technical safeguards to ensure secure email communications; and. The CE also initiated plans to implement an improved risk management process.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.