Protected health information belonging to more than 45,000 people has been compromised in two separate incidents disclosed this week.
Kaiser Permanente Colorado Wednesday confirmed that a laptop containing information such as the name, gender, date of birth, member identification numbers and physician information of approximately 38,000 members was stolen from the car of an employee in California.
“The data included on the laptop was part of a review of an internal health quality project and is limited to two Kaiser Permanente Colorado medical offices: Skyline and Southwest,” the company said in a statement.
Though the theft occurred on Oct. 4, Kaiser began notifying affected members of the incident only this week. The reason for the delay: Kaiser’s IT staff needed time to go through “hundreds of thousands of files” to figure out exactly what information was on the stolen laptop and how many people might be affected, said Jacque Montgomery, a Kaiser spokeswoman.
All of the information on the laptop was password-protected, and at least some of it was encrypted, she said. “Everything indicates that the laptop was stolen for its value and not for the information in it.”
The letters sent out by Kaiser explains the security breach and advises members on what to do if they believe their information was being misused in some way, she said. The company has also set up a special phone line to answer questions related to the incident.
This is the second time this year that Kaiser has had to send out letters to members informing them of a potential data compromise. In August, the company sent letters to more than 160,000 members alerting them of potential ID theft concerns after a laptop containing their data was stolen.
Meanwhile, in a similar incident, two computers containing health records on more than 7,000 people in the Indiana Breast and Cervical Cancer Program were stolen earlier this month. The computers were taken from a health center in Jeffersonville, Ind., that manages the state program, said Erik Deckers, a spokesman for the Indiana Department of Health.
The compromised information includes the names, Social Security numbers and medical histories of the affected individuals, Deckers said. So far, there is no indication that any of the data has been misused, he said, adding that letters have been sent out to 7,070 people informing them of the potential compromise of personal information.




