- State
- AL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 20,744
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Network Server, Other, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 4, 2011, covered entity’s (CE) facility was broken into and a computer server, three desktop computers, and an external hard drive were stolen, affecting the demographic, clinical and financial information of approximately 20,744 individuals. The CE, Rape & Brooks Orthodontics, P.C., provided breach notification to HHS, affected individuals, and the media. As a result of this incident, the CE increased physical security by upgrading its alarm system, changing and installing additional locks, and storing its server in a locked data closet. The CE also improved technical safeguards by implementing double-layered password protection on its computers and encrypting data on external hard drives. OCR obtained and reviewed the CE’s relevant HIPAA policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.