- State
- KS
- Covered entity type
- Healthcare Provider
- Individuals affected
- 7,757
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 13, 2012, a laptop computer was from stolen from an employee’s vehicle. The laptop contained the electronic protected health information (ePHI) of approximately 7,757 Kansas Department on Aging customers. The ePHI included customers’ names, addresses, dates of birth, types of services, case managers and their telephone numbers, dates of quality reviews, and names of quality review staff. KDOA filed a police report, provided breach notification to HHS, affected individuals, and the media, and issued substitute notice. Following the breach, KDOA retrained its workforce and encrypted all its laptops and thumb/flash drives. OCR obtained assurances that KDOA implemented the corrective action listed above, and upon investigation, OCR determined that KDOA does not meet the definition of a covered entity.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.