- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,490
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On May 1, 2012, an unencrypted laptop of a University of Kentucky Health Care employee with the protected health information (PHI) of approximately 4,488 individuals was stolen from a workforce member’s son, who borrowed the laptop without permission and knew the computer’s password. The PHI involved in the breach included medical record numbers, dates of visits, and chief complaints. The covered entity (CE) provided breach notification to HHS, the media, and affected individuals, set up a toll-free number for questions, and posted substitute notice on its website. The responsible workforce member was suspended pending an investigation and ultimately resigned. The CE created and revised its HIPAA policies and procedures, including its mobile device policy, and implemented additional security measures to address high and moderate risks identified in its risk analysis. Finally, the CE provided evidence of employee training and security reminders. OCR obtained assurances that the corrective actions listed above were completed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.