Back to the register

Aultman Hospital

ArchivedSubmitted 08/05/2010
State
OH
Covered entity type
Healthcare Provider
Individuals affected
13,867
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

A password-protected laptop, which was maintained by the covered entity (CE), Aultman Hospital, was stolen from an employee’s car, which contained the electronic protected health information (ePHI) of approximately 13,867 individuals, including patients’ names, dates of birth, telephone numbers, social security numbers, insurance identification, and health information related to home health services. The CE provided breach notification to HHS, affected individuals, and the media, posted notification of the breach on its website, and reported the theft to the local police department. The CE also offered one year of free credit monitoring services to affected individuals. Following the breach, the CE revised its HIPAA policies and procedures, enhanced encryption and updated software on its laptops, sanctioned employee(s) involved in the breach incident, and retrained its workforce on the revised policies and procedures. OCR obtained documentation evidencing that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.