- State
- MN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 20, 2012, one of the covered entity's (CE) clinic locations in St. Paul, Minnesota, was burglarized and two tablet computers containing electronic protected health information (ePHI) were stolen. The computers contained demographic information for approximately 4,000 individuals. Upon discovering the breach, the CE, Family Health Services' of Minnesota, P.A., reported the breach incident to the Saint Paul Police Department. The CE also provided breach notification to the individuals affected by the breach, HHS, and the media. To prevent similar breaches from happening in the future, the CE improved safeguards for storage of its laptop computers and encrypted its computer hard drives. The CE also conducted a security risk analysis, prepared an incident report, and updated its policy and procedure regarding the safeguarding of PHI, and trained its workforce on its updated policies and procedures. OCR obtained documented assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.