City of Homer Data Breach
City of Homer Portable Device Loss Exposes 1,412 Residents
What happened in the City of Homer data breach?
The City of Homer data breach was reported on December 7, 2023 and affected 1,412 individuals. The breach type was Loss involving Other Portable Electronic Device. This breach occurred in Alaska. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
City of Homer Breach Details
Data Breach Report: City of Homer Portable Electronic Device Loss
Incident Overview
On December 7, 2023, the City of Homer, Alaska reported a data breach involving the loss of a portable electronic device containing protected health information (PHI) and personally identifiable information (PII) affecting 1,412 individuals. The breach was classified as a loss incident, indicating that a mobile device or portable storage medium containing sensitive data was misplaced, lost, or otherwise removed from the entity's control without authorization. This type of incident represents a significant vulnerability in data security protocols, as portable devices are inherently mobile and difficult to track once they leave secure facilities.
Discovery and Response Timeline
The City of Homer discovered the loss of the portable electronic device and initiated an investigation to determine the scope and nature of the data compromise. Upon discovery, the organization followed HIPAA Breach Notification Rule requirements by conducting a risk assessment to determine whether notification to affected individuals was necessary. The submission date of December 7, 2023 indicates that the entity completed its investigation and determined that notification was required within the 60-day window mandated by federal regulations. The organization's response included documenting the incident, identifying all affected individuals, and preparing breach notification communications in accordance with 45 CFR §164.400-414.
Breach Mechanism and Technical Details
The breach involved a portable electronic device, which typically refers to mobile devices such as laptops, tablets, smartphones, USB drives, external hard drives, or other compact computing equipment capable of storing data. Portable devices represent a significant security risk in healthcare settings because they are frequently transported between locations, are susceptible to theft or loss, and may not have the same level of encryption or security controls as stationary network infrastructure. The loss of such a device suggests that either the device was not adequately secured with encryption, was not tracked through mobile device management (MDM) systems, or was accessed by an unauthorized party after being lost. Without confirmation of encryption status, there is a reasonable assumption that the data on the device may have been accessible to anyone who obtained possession of it.
Organizational Context
The City of Homer is a municipal government entity located in Alaska, serving as the administrative center for the Kenai Peninsula Borough. As a government organization, the City of Homer likely maintains health information through various municipal services, including employee health records, public health programs, or health-related administrative functions. Municipal entities often handle health data through employee benefits programs, occupational health services, public health initiatives, or contracted health services. The scope of operations for a city government in Alaska typically includes administrative staff, public health coordination, and potentially health screening or vaccination programs. The loss of a portable device from a municipal entity suggests inadequate data security protocols for mobile computing devices used by city employees or contractors.
Impact on Affected Individuals
Approximately 1,412 individuals were affected by this breach, representing a significant portion of the City of Homer's population and potentially including city employees, their dependents, and residents who interacted with city health services. The affected individuals were notified of the breach in accordance with HIPAA requirements, which mandate notification without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. The notification likely included information about the types of data exposed, the date of the loss, steps the organization was taking to investigate, and recommended actions for individuals to protect themselves from potential misuse of their information. Affected individuals should have received guidance on credit monitoring, fraud detection, and identity theft protection resources.
Data Security and HIPAA Compliance Implications
This incident highlights critical gaps in the City of Homer's data security practices, particularly regarding the protection of portable electronic devices. Under HIPAA's Security Rule (45 CFR §164.300-318), covered entities and business associates must implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Specific requirements include device and media controls (§164.310(d)), which mandate policies and procedures to govern the receipt, removal, reuse, and disposal of electronic media containing ePHI. The loss of a portable device suggests potential violations of these requirements, including inadequate encryption, insufficient device tracking, or failure to implement access controls. The absence of a business associate in this breach indicates that the City of Homer was directly responsible for the data and the security failure. Similar incidents involving portable device losses have been reported across healthcare organizations, with the HHS Office for Civil Rights (OCR) consistently emphasizing that encryption of portable devices is a critical control to mitigate breach risk. Organizations that fail to encrypt portable devices containing ePHI face increased regulatory scrutiny and potential enforcement actions.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the City of Homer Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills for unauthorized services or claims; contact your health insurance provider immediately if you identify suspicious activity
Change passwords for any online accounts associated with the City of Homer or health-related services, using strong, unique passwords that are not reused across multiple accounts
Enroll in identity theft protection services if offered by the City of Homer as part of breach remediation; consider purchasing identity theft insurance for comprehensive protection against financial and medical identity theft
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you suspect identity theft or fraudulent activity; maintain documentation of all communications and incidents related to the breach
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Alaska Breaches
Search all breaches reported in Alaska