- State
- IN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Two unencrypted desktop computers and one unencrypted laptop computer storing electronic protected health information (ePHI) of approximately 2,000 individuals were stolen from the covered entity’s (CE) premises during a break-in on September 15, 2010. The ePHI involved in the breach included patients’ names, thermal imaging scans, patients’ contact information, insurance information, and social Security numbers. The CE investigated the incident and reported the theft to the local police department. It also provided breach notification to HHS, the media, and affected individuals. Following the breach, the CE moved to a new facility with a security system. As a result of OCR’s investigation, the CE developed and implemented a policy and procedure related to compliance with the Breach Notification Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.