Coplin Health Systems (WV) reported to HHS OCR on 2017-12-29 the theft of a password-protected but unencrypted laptop issued to a part-time employee, stolen from his vehicle. The laptop was used to access the CE's EHR and email systems. The CE could not rule out that PHI from prior users remained on the device. Approximately 43,000 individuals were affected. Credentials were immediately revoked, systems monitored, and all remaining laptops encrypted or decommissioned. A mobile device management solution was also implemented.
Affected (this filing): 43,000