On July 27, 2020, the Office for Civil Rights (OCR) under the U.S. Department of Health & Human Services (HSS) announced a settlement with Lifespan Health System Affiliated Covered Entity (Lifespan), in which Lifespan agreed to pay $1,040,000 following an April 2017 breach concerning the theft of an unencrypted employee laptop.
The theft resulted in a breach of 20,431 individuals’ electronic protected health information (ePHI), including “patients’ names, medical record numbers, demographic information, and medication information.”