Back to the register

Stanford Hospital & Clinics and School of Medicine, Privacy Manager Breach

ArchivedSubmitted 08/03/2012
State
CA
Covered entity type
Healthcare Provider
Individuals affected
2,300
Business associate present
No
Type of breach
Theft
Location of breached information
Desktop Computer
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Stanford Health Care (SHC)(formerly Stanford Hospital and Clinics), and Stanford School of Medicine (SOM), reported that on July 15 or 16, 2012, a password-protected computer was stolen from a locked SOM workforce member's office. The electronic protected health information (ePHI) of approximately 2,641 individuals may have been affected by this incident. The ePHI involved in the breach included clinical and demographic information related to SHC patient care and SOM research. The CE reported that there was no evidence to indicate that ePHI had been inappropriately accessed. The CE contacted law enforcement, notified the affected individuals, offered identity protection services at no cost to the affected individuals, established a toll-free call center to assist affected individuals with questions or concerns, and notification the media and HHS. As a result of the breach and OCR’s corresponding investigation, the CE implemented additional physical safeguards, audited SCH desktops and laptops to ensure encryption, issued security awareness reminders to workforce, and initiated plans to implement an improved risk management process.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.