On May 25, 2014, a password-protected but unencrypted laptop containing the PHI of 38,906 patients was stolen from Self Regional Healthcare's administrative offices in SC during a break-in. Breached data included names, SSNs, driver's license numbers, treating physician names, insurance policy numbers, account numbers, service dates, diagnosis/procedure information, payment card data, financial account information, and possibly addresses. The CE notified HHS, media, and individuals; offered credit monitoring; engaged police; revised HIPAA policies; retrained staff; improved physical access controls; and encrypted computers. OCR obtained assurances of corrective action.
Affected (this filing): 38,906