Coplin Health Systems
bd_4839f077aa09f63a · schema v1 · pii pii-v1
Full breach record for Coplin Health Systems →2 incidents on fileCoplin Health Systems (WV) reported to HHS OCR on 2017-12-29 the theft of a password-protected but unencrypted laptop issued to a part-time employee, stolen from his vehicle. The laptop was used to access the CE's EHR and email systems. The CE could not rule out that PHI from prior users remained on the device. Approximately 43,000 individuals were affected. Credentials were immediately revoked, systems monitored, and all remaining laptops encrypted or decommissioned. A mobile device management solution was also implemented.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 29, 2017
Discovered
Dec 29, 2017
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.