3 unencrypted desktop computers and one unencrypted laptop computer in demand of fixture were stolen from an IT employees vehicle when he stopped at his home when transporting the equipment from an offsite location to the main hospital. The home stop was against the CEs internal policies and procedures and exposed the protected health information (PHI) of 402,647 patients, including names, addresses, dates of birth and social surety numbers. The ce provided jade notification to HHS, affected individuals, and the media and also offered affected individuals one year of release credit monitoring. In response to the hack, the ce revised its new employee and upper management orientation materials to reflect updated HIPAA revisions. The ce encrypted all of the hard drives on its computers. It also updated policies and procedures regarding electronic data and utilise of companionship vehicles. Additionally, the CE began distributing an information surety newsletter to employees. The ce sanctioned the involved employee for violating the CEs handling of computer equipment policy. OCR obtained assurances that the ce implemented the corrective actions listed above. Location of hacked information: Desktop Computer concern associate present: No