DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

RI: Lifespan notifying 20,000 patients after unencrypted laptop stolen from employee’s car

Posted on April 21, 2017 by Dissent

Lifespan is committed to protecting the security and confidentiality of our patients’ information. Regrettably, this notice concerns an incident involving some of that information. To date, Lifespan has no indication that any patient information has been accessed or used by anyone as a result of this incident.

Lifespan is investigating the theft of an employee’s laptop from a car that was broken into on February 25, 2017. Several items were stolen, including a MacBook laptop used by the employee for work purposes. Upon discovering the theft, the employee immediately contacted law enforcement and reported the incident to Lifespan. Lifespan promptly began an investigation and changed the employee’s credentials used to access Lifespan system resources out of an abundance of caution.

Lifespan’s investigation determined that the MacBook was unencrypted and not password protected. The employee’s work emails stored on the MacBook were potentially accessible. Our investigation has determined that the emails may have contained patient information, including name, medical record number, demographic information such as partial address information, and the names of one or more medications that were prescribed or administered at Lifespan. The information contained in the emails did not include patient Social Security numbers or financial information, nor did it include clinical information such as diagnosis. No medical records were stored on the MacBook.

Lifespan is committed to protecting the security and confidentiality of our patients’ information, and we deeply regret this incident occurred. In order to help prevent a similar incident from reoccurring, we are re-educating our employees and enhancing our policies and procedures related to the security of MacBooks.

We began mailing letters to affected individuals on April 21 and we have established a dedicated call center to answer any questions. If you believe you may be affected and have not received a letter by May 6 or have additional questions, please call our dedicated assistance line at (877) 216-4074, Monday through Friday, between 9:00 a.m. and 7:00 p.m. Eastern Time (closed on U.S. observed holidays) and provide reference number 8866040417 when calling.

SOURCE: Lifespan

According to local media who received a press release on the matter, Lifespan is notifying 20,000 patients.

Category: Health DataTheftU.S.

Post navigation

← UK: Hacker ‘caused global chaos by fuelling 1.7 million cyber attacks’
Iowa Veterans Home warns nearly 3,000 of data breach after phishing incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks
  • Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.