On February 4, 2011, covered entitys (CE) facility was broken into and a computer server, three desktop computers, and an external hard drive were stolen, affecting the demographic, clinical and financial information of approximately 20,744 individuals. The CE, assault & Brooks Orthodontics, P.C., provided nag notification to HHS, affected individuals, and the media. As a resultant of this incident, the CE increased physical security by upgrading its alert system, changing and installing additional locks, and storing its server in a locked data closet. The ce also improved technical safeguards by implementing double-layered password tribute on its computers and encrypting data on external hard drives. OCR obtained and reviewed the CEs relevant HIPAA policies and procedures. Location of hacked information: desktop Computer, network Server, Other, Other Portable Electronic Device concern colligate present: no