- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 554
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee’s car was broken into and a tote bag, which had a paper spreadsheet containing protected health information (PHI), was stolen. The spreadsheet contained PHI pertaining to 554 patients and included patients’ names, ages, weight, race, social security numbers, and blood and tissue typing. The covered entity (CE), North Carolina Baptist Hospital, provided breach notification to HHS, affected individuals, and the media, and offered affected individuals a year of credit monitoring services along with a toll-free number to contact. Following the breach, the CE reviewed the applicable policies and procedures with the clinic responsible, revised the spreadsheet to no longer include patients’ social security numbers, and counseled and warned the involved employee about the requirements for properly safeguarding PHI. Additionally, the Chief Executive Officer of the Medical Center emailed all employees to re-educate them about the importance of properly safeguarding PHI and the expectations for compliance and commitment to adhering to federal and state privacy and security laws. As a result of OCR’s investigation, the CE provided an alternate, secure way to electronically access the clinic spreadsheet, installed video cameras in the parking dock, and externally inspected employee vehicles to assure no PHI was visible. The CE established a Privacy and Information Security Council to help identify ways to improve and strengthen privacy and security policies and practices.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.