- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,700
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR opened an investigation of the covered entity (CE), Titus Regional Medical Center, after it reported that its EMS laptop computer that contained the protected health information (PHI) of 5,840 patients was missing upon returning from the EMS's last transport to Titus. It is thought that the laptop was left on the fender of the vehicle and fell off. Although the laptop was encrypted, the CE could not confirm if the laptop was opened or closed when it dropped from the vehicle. If the laptop was open when it dropped, then patients’ PHI (names, social security numbers, addresses, and dates of birth) may have been accessible to others. The CE proved breach notification to HHS, affected individuals, and the media. Following the breach the CE conducted an internal audit and determined that there was a glitch in the software parameter that permitted the download and storage of all 5,840 patients’ records on the laptops regardless of the parameter setting. As a result of OCR’s investigation the settings on the laptops were changed, including a reduction in the time for automatic shut–off when laptops are not in use. The CE applied sanctions to the EMT personnel involved and re-trained them on its privacy policies. In November 2013, the CE conducted a system wide risk analysis that included all of its systems and revised and implemented its security policies.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.