- State
- PR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Hospital Auxilio Mutuo de Puerto Rico, Inc., reported that on November 9, 2010, an employee resigned his position and removed two computer hard drives and a laptop computer that contained electronic protected health information (ePHI), potentially affecting over 30,000 individuals. The CE initially reported that the breached ePHI included names, addresses, zip codes, dates of births, social security numbers, diagnostic conditions and other treatment information. During the investigation, the CE retrieved the hard drives and laptop and determined that the hard drives contained confidential financial information and business making decisions by the CE, and did not include the types of identifiers (e.g. patient names, Social Security numbers, home addresses, etc.) that could be used to re-identify an individual. Thus, the CE determined that the theft did not constitute a breach of ePHI. Further, the CE determined that the laptop was an information technology department laptop that only contained financial data and upper management e-mails. As of the result of OCR’s investigation, OCR has required the CE to conduct a risk analysis, implement a risk management plan, revise its policies and procedures, and re-train its staff.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.