- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,972
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unsecured tablet computer was stolen from an employee’s vehicle on January 6, 2012. The protected health information (PHI) involved in the breach included names, addresses, dates of birth, treating physicians’ names and health screening results for 1,972 individuals. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. As a result of OCR’s investigation, OCR reviewed the CE’s HIPAA policies, documentation of workforce training related to safeguarding mobile devices, and its risk analysis related to mobile devices. Following the incident, the CE implemented additional technical safeguards, including encryption solutions, as part of its mobile device management program.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.