DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

RI: Lifespan notifying 20,000 patients after unencrypted laptop stolen from employee’s car

Posted on April 21, 2017 by Dissent

Lifespan is committed to protecting the security and confidentiality of our patients’ information. Regrettably, this notice concerns an incident involving some of that information. To date, Lifespan has no indication that any patient information has been accessed or used by anyone as a result of this incident.

Lifespan is investigating the theft of an employee’s laptop from a car that was broken into on February 25, 2017. Several items were stolen, including a MacBook laptop used by the employee for work purposes. Upon discovering the theft, the employee immediately contacted law enforcement and reported the incident to Lifespan. Lifespan promptly began an investigation and changed the employee’s credentials used to access Lifespan system resources out of an abundance of caution.

Lifespan’s investigation determined that the MacBook was unencrypted and not password protected. The employee’s work emails stored on the MacBook were potentially accessible. Our investigation has determined that the emails may have contained patient information, including name, medical record number, demographic information such as partial address information, and the names of one or more medications that were prescribed or administered at Lifespan. The information contained in the emails did not include patient Social Security numbers or financial information, nor did it include clinical information such as diagnosis. No medical records were stored on the MacBook.

Lifespan is committed to protecting the security and confidentiality of our patients’ information, and we deeply regret this incident occurred. In order to help prevent a similar incident from reoccurring, we are re-educating our employees and enhancing our policies and procedures related to the security of MacBooks.

We began mailing letters to affected individuals on April 21 and we have established a dedicated call center to answer any questions. If you believe you may be affected and have not received a letter by May 6 or have additional questions, please call our dedicated assistance line at (877) 216-4074, Monday through Friday, between 9:00 a.m. and 7:00 p.m. Eastern Time (closed on U.S. observed holidays) and provide reference number 8866040417 when calling.

SOURCE: Lifespan

According to local media who received a press release on the matter, Lifespan is notifying 20,000 patients.

Related posts:

  • Lifespan Pays $1,040,000 to OCR to Settle Unencrypted Stolen Laptop Breach
Category: Health DataTheftU.S.

Post navigation

← UK: Hacker ‘caused global chaos by fuelling 1.7 million cyber attacks’
Iowa Veterans Home warns nearly 3,000 of data breach after phishing incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Texas Centers for Infectious Disease Associates Notifies Individuals of Data Breach in 2024
  • Battlefords Union Hospitals notifies patients of employee snooping in their records
  • Alert: Scattered Spider has added North American airline and transportation organizations to their target list
  • Northern Light Health patients affected by security incident at Compumedics; 10 healthcare entities affected
  • Privacy commissioner reviewing reported Ontario Health atHome data breach
  • CMS warns Medicare providers of fraud scheme
  • Ex-student charged with wave of cyber attacks on Sydney uni
  • Detaining Hackers Before the Crime? Tamil Nadu’s Supreme Court Approves Preventive Custody for Cyber Offenders
  • Potential Cyberattack Scrambles Columbia University Computer Systems
  • 222,000 customer records allegedly from Manhattan Parking Group leaked

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina
  • European Commission publishes its plan to enable more effective law enforcement access to data
  • Sacred Secrets: The Biblical Case for Privacy and Data Protection
  • Microsoft’s Departing Privacy Chief Calls for Regulator Outreach
  • Nestle USA Settles Suit Over Job-Application Medical Questions

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.