On February 23, 2015, Amedisys, Inc. (LA) discovered that 142 encrypted computers and laptops were unaccounted for, accessible to former employees who had left or been terminated between January 1, 2011 and December 31, 2014. The devices contained ePHI of approximately 6,909 individuals, including names, dates of birth, addresses, SSNs, diagnoses, lab results, medications, treatment info, and claims. Breach notification was sent to HHS, individuals, and media. Remediation included enhanced termination/device recovery policies and an offline device freeze capability. Breached information located on Desktop Computer, Electronic Medical Record, and Laptop.
Affected (this filing): 6,909