- State
- VA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,873
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity’s (CE) backup hard drive was stolen from the physician’s car, along with a camera and prescription pads. All the items were thrown aside except for the hard drive. The PHI involved in the breach consisted mainly of names and clinic notes of 4,873 individuals, while dates of birth were involved in some instances. Some photos of patients’ hands were also involved. Following the breach, the CE filed a police report. As a result of OCR’s investigation, the CE updated HIPAA policies, re-trained staff at all levels, and contracted with a third party to provide record storage service and encryption.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.