JAN 2, 2013 5:26pm ET

Related Links

University Settles with Feds After HIPAA Violations
May 22, 2013
Data Entry Error Leads to Data Breach at LSU
May 21, 2013
Quick Turnaround on Breach Notification
May 17, 2013
California Developing Guidance for Patient Consent of HIE
May 17, 2013
Hacker Gets Patient Credit Cards from North Carolina Providers
May 16, 2013
OCR Seminars to Walk through Omnibus HIPAA Rule
May 16, 2013
PHI Breach #3 for Indiana University
May 15, 2013

Hospital Notifies Six Years Worth of Patients After Breach

JAN 2, 2013 5:26pm ET
Print
Reprints
Email

A stolen, unencrypted laptop computer has caused 25-bed Gibson General Hospital in Princeton, Ind., to notify all 29,000 patients treated during the past six years of a breach of their protected health information.

The password-protected laptop was among the items stolen during a burglary of an employee’s home on Nov. 27, 2012, according to the hospital. Some employees are permitted to bring home laptops; the employee required 24-hour access to the electronic health records system, according to the hospital.

The laptop has not been found and the hospital cannot determine which patients had information on it, so it is notifying all patients since January 2007 when the EHR was implemented. But the clinical records contain names, addresses, Social Security numbers and treatment details, among other information. There is no indication the data has been accessed, according to a notice to patients.

Gibson General Hospital is offering affected patients one year of free credit monitoring and identity theft protection services. Gibson General is the only hospital in Gibson County with a population of about 33,500.

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.