DisclosureLens
WEST VIRGINIAPhysicalHealthcareHealthcareTheftCustomer Data InvolvedHealth (basic)Identity (basic)MediumResolved

Coplin Health Systems

bd_4839f077aa09f63a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 29, 2017

Filed

Dec 29, 2017

To disclose

Affected

43,000

Confidence

97%
Full breach record for Coplin Health Systems2 incidents on file

Coplin Health Systems (WV) reported to HHS OCR on 2017-12-29 the theft of a password-protected but unencrypted laptop issued to a part-time employee, stolen from his vehicle. The laptop was used to access the CE's EHR and email systems. The CE could not rule out that PHI from prior users remained on the device. Approximately 43,000 individuals were affected. Credentials were immediately revoked, systems monitored, and all remaining laptops encrypted or decommissioned. A mobile device management solution was also implemented.

HIPAA clock HHS report on time
filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.

Incident timeline

discovery → filing · ≤1 day / 0 days

Dec 29, 2017

Discovered

Dec 29, 2017

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed43,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.