Institutions

Concentra Health Services: The HHS Investigation Into an Unencrypted Laptop Theft That Exposed 870,000 Patient Records

HHS found Concentra Health Services had failed to implement encryption on laptop computers containing protected health information for thousands of patients — a risk assessment failure that resulted in a breach of 870,000 patient records when an unencrypted laptop was stolen, and a $1.725 million HIPAA resolution agreement.

Concentra Health Services Inc., a national network of occupational health clinics that provides workers' compensation care, employee health services, and urgent care to businesses and their employees, entered into a $1.725 million HIPAA resolution agreement with the Department of Health and Human Services Office for Civil Rights after an unencrypted laptop containing protected health information for approximately 870,000 patients was stolen from a Concentra facility — a breach that HHS investigators found resulted from the company's failure to implement a risk management program that adequately identified and addressed the risk of unencrypted portable devices containing sensitive patient information.DOCUMENTED

The Concentra case was a landmark in HIPAA enforcement because HHS's investigation found not just the breach itself but a prior risk assessment that had identified portable device encryption as a security risk — and a subsequent failure to implement adequate remediation of that identified risk within a reasonable timeframe. The enforcement action established that HIPAA covered entities can face significant penalties when they identify security risks through required risk assessments and then fail to address those risks before a breach occurs.

Key facts
  • An unencrypted laptop containing 870,000 patient records was stolen from a Concentra facility.
  • HHS found Concentra's prior risk assessment had identified portable device encryption as a risk but remediation was inadequate.
  • The $1.725 million HIPAA resolution agreement was among the largest civil monetary penalties at the time of settlement.
  • The breach exposed protected health information including clinical records for occupational health and workers' compensation patients.
  • The resolution agreement required a comprehensive corrective action plan addressing encryption and device security across Concentra's network.

The Laptop Theft and Breach Discovery

The protected health information that was exposed when the laptop was stolen included names, Social Security numbers, dates of birth, addresses, telephone numbers, and clinical and treatment information for Concentra patients — the full scope of information that occupational health records contain, including sensitive workers' compensation injury and treatment details that patients have strong privacy interests in protecting. The stolen device had not been encrypted, meaning that any person who obtained the device had the ability to access the patient data stored on it without any authentication or decryption barrier. When Concentra reported the theft to HHS as required under HIPAA's breach notification rules, the subsequent investigation focused on why the device had not been encrypted given HIPAA's requirements for risk management and safeguarding of protected health information.REVIEWED

HIPAA's Security Rule requires covered entities to implement technical safeguards that protect electronic protected health information, including encryption and decryption procedures when required by the entity's risk analysis. The Security Rule does not mandate encryption in all circumstances — it specifies that where encryption is not used, the entity must implement an equivalent alternative measure — but requires a documented analysis of whether the risks associated with unencrypted portable devices require encryption as a safeguard. When that analysis concludes that encryption is a required safeguard and the entity does not implement it, the entity faces Security Rule violation exposure.DOCUMENTED

The Risk Assessment Failure

The most significant finding in HHS's investigation of Concentra was that the company had conducted a prior risk assessment that had identified the risk of unencrypted portable devices containing protected health information as a security concern requiring remediation. This prior assessment represented an acknowledgment by Concentra's own security program that the encryption gap was a recognized risk — but the company had not implemented adequate encryption or equivalent alternative safeguards on its portable devices within a timeframe consistent with the significance of the identified risk. When the theft occurred, the risk that the assessment had identified had not been addressed, resulting in exactly the harm the assessment had flagged as a possibility.REVIEWED

This sequence — risk identified, remediation delayed, breach occurs — is the most straightforward case for HIPAA enforcement action because the covered entity cannot argue that the risk was unforeseeable or that it lacked information that would have prompted protective action. The entity had conducted the required analysis, reached the correct conclusion that encryption was necessary, and then failed to act on that conclusion with adequate speed and effectiveness. HHS's enforcement in this context serves the clear deterrence purpose of ensuring that risk assessments are not merely compliance documents but actual drivers of security program improvements implemented within reasonable timeframes.

A risk assessment that identifies an encryption gap and then sits in a drawer while the unencrypted laptops keep circulating has not reduced any risk. It has created a paper trail proving the organization knew what was wrong and chose not to fix it in time.

Occupational Health Records and Patient Privacy

The protected health information in occupational health and workers' compensation records carries particular sensitivity for the patients involved. Workers who have filed workers' compensation claims or who have sought occupational health services for work-related conditions may have strong interests in controlling who can access information about their injuries, treatment, and medical limitations — information that, if improperly disclosed to employers or others, could affect employment status, insurance coverage, or professional reputation. The connection between occupational health records and employment creates a dimension of potential harm from unauthorized disclosure that goes beyond the general privacy harm from exposure of medical information. Concentra patients whose records were exposed in the laptop theft faced this compound risk, and the $1.725 million penalty reflected HHS's assessment of the significance of the breach and the severity of the underlying compliance failure.DOCUMENTED

The corrective action plan required by the resolution agreement addressed not just the specific encryption failure but Concentra's broader security program — requiring comprehensive risk analysis updates, policies and procedures governing portable device security, workforce training on security responsibilities, and ongoing monitoring to ensure that the organization's security program remained adequate to protect the sensitive occupational health data it processed across its national clinic network.

Encryption as a Standard of Care in Healthcare

The Concentra case helped establish full-disk encryption of portable devices containing protected health information as an expected standard of practice in healthcare security — a baseline measure whose absence requires specific justification and equivalent alternative safeguards. In the decade since the Concentra resolution, encryption of mobile devices has become nearly universal in healthcare organizations with serious security programs, and the cost and technical complexity of implementing encryption has declined dramatically as built-in device encryption has become standard in major operating systems. The enforcement environment the Concentra case helped establish has accelerated this adoption, ensuring that the practical security improvement — protecting millions of patients from the consequences of stolen or lost devices — was achieved alongside the regulatory accountability it represented.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →