Jackson Lewis P.C. Data Breach
Jackson Lewis P.C. Portable Device Theft Exposes 986 Individuals
What happened in the Jackson Lewis P.C. data breach?
The Jackson Lewis P.C. data breach was reported on February 17, 2023 and affected 986 individuals. The breach type was Theft involving Other Portable Electronic Device. This breach occurred in California. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Jackson Lewis P.C. Breach Details
Jackson Lewis P.C. Data Breach Report
Incident Overview
Jackson Lewis P.C., a prominent employment law firm headquartered in California, reported a data breach on February 17, 2023, involving the theft of a portable electronic device. The breach resulted in the unauthorized access to protected health information (PHI) belonging to approximately 986 individuals. As a business associate to healthcare entities, Jackson Lewis P.C. maintains sensitive patient and employee health information as part of its legal services and benefits administration work. The theft of the portable device created a significant risk of exposure for personal health data that may have included names, contact information, medical histories, and potentially other sensitive identifiers.
Discovery and Response Timeline
The entity discovered the breach through the loss of the portable electronic device, which was reported missing on or around the submission date of February 17, 2023. Upon discovery, Jackson Lewis P.C. initiated an investigation to determine the scope of data potentially compromised and the nature of information stored on the device. The firm worked to identify all affected individuals and began the process of notifying impacted parties in accordance with HIPAA Breach Notification Rule requirements. As a business associate, Jackson Lewis P.C. was obligated to notify its covered entity clients, who in turn were responsible for notifying affected individuals. The investigation focused on determining whether the device contained unencrypted PHI and assessing the likelihood of unauthorized access or misuse of the compromised information.
Breach Mechanism and Technical Details
The breach involved the theft of a portable electronic device, which typically refers to laptops, tablets, mobile phones, or external storage devices such as USB drives or portable hard drives. Portable devices represent a significant vulnerability in healthcare data security because they are mobile, easily lost or stolen, and may not always have strong encryption or access controls in place. The theft vector suggests that the device was either left unattended in a public location, taken from an employee's vehicle or home, or removed from the workplace without proper authorization. Portable electronic devices used in legal and healthcare administration settings often contain cached data, temporary files, or unencrypted copies of sensitive information that may persist even after deletion. The lack of physical security controls and the portability of such devices make them attractive targets for theft, whether for opportunistic gain or targeted data harvesting. Without confirmation of encryption status, the exposure risk is elevated, as thieves would have direct access to any unencrypted data on the device.
Organizational Context
Jackson Lewis P.C. is one of the largest employment law firms in the United States, with offices across multiple states including California. The firm provides legal services related to employment law, benefits administration, and workplace compliance matters. As a business associate under HIPAA, Jackson Lewis P.C. handles health information on behalf of covered entities such as employers, health plans, and healthcare providers. The firm's role typically involves managing employee health benefits, administering wellness programs, handling COBRA administration, and providing legal counsel on health-related employment matters. The organization's size and multi-state operations mean it processes significant volumes of health information across numerous client relationships. The breach affects individuals whose information was stored on the compromised portable device, which may have included employees of Jackson Lewis P.C.'s client organizations or individuals whose health data was being processed as part of benefits administration services.
Impact on Affected Individuals
Approximately 986 individuals were affected by this breach. These individuals likely include employees of Jackson Lewis P.C.'s client companies whose health information was stored on the stolen device, as well as potentially beneficiaries or dependents whose data was included in benefits administration files. The affected population spans California and potentially other states where Jackson Lewis P.C. maintains operations and client relationships. Notification of the breach was required under the HIPAA Breach Notification Rule, which mandates that covered entities and business associates notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. Given the February 17, 2023 submission date, notifications would have been required to be sent by mid-April 2023. The firm was also required to notify the U.S. Department of Health and Human Services (HHS) and, depending on the number of affected individuals in each state, potentially state attorneys general and media outlets.
Data Exposure and Risk Assessment
The specific data types exposed depend on the contents of the stolen portable device. Given Jackson Lewis P.C.'s role as a business associate, the device likely contained some combination of the following: names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, health insurance information, medical histories, medication lists, health conditions, claims information, and potentially financial account details related to benefits administration. The exposure of such information creates multiple risks for affected individuals, including identity theft, medical identity theft, fraudulent insurance claims, and targeted phishing or social engineering attacks. The lack of confirmed encryption on the device elevates these risks significantly, as thieves would have immediate access to readable data without requiring additional technical skills to decrypt information. Individuals whose Social Security numbers or financial information were exposed face heightened risk of financial fraud and identity theft.
HIPAA Compliance and Industry Context
Under HIPAA's Security Rule, covered entities and business associates are required to implement administrative, physical, and technical safeguards to protect electronic PHI. The theft of an unencrypted portable device represents a failure of physical safeguards, which should include controls to prevent unauthorized access to devices containing PHI. HIPAA regulations specifically require that portable devices containing PHI be encrypted or that the data be rendered unreadable through other means. Portable device theft remains one of the most common causes of healthcare data breaches, accounting for a significant percentage of reported incidents annually. The 2023 HIPAA breach landscape shows that theft and loss of portable devices continue to be a leading breach vector, often resulting from inadequate device management policies, insufficient employee training, and lack of encryption enforcement. This incident is consistent with broader industry trends showing that healthcare organizations and business associates must strengthen controls over mobile devices and implement mandatory encryption for all devices that store or access PHI.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Jackson Lewis P.C. Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for at least 12 months following notification of the breach. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized account opening.
Review medical records and explanation of benefits (EOB) statements from your health insurance provider for any unauthorized claims or services you did not receive. Contact your health plan and healthcare providers immediately if you identify suspicious activity.
Change passwords for any online accounts associated with health insurance, benefits administration portals, or healthcare providers, particularly if the same password is used across multiple accounts. Use strong, unique passwords for each account.
Consider enrolling in identity theft protection or credit monitoring services if offered by Jackson Lewis P.C. or the affected covered entity. Many breaches include complimentary monitoring services for affected individuals.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and obtain an Identity Theft Report to help dispute fraudulent accounts.
Contact your state's Attorney General office to report the breach and inquire about additional protections or resources available to California residents.
Remain vigilant for suspicious communications claiming to be from healthcare providers, insurance companies, or financial institutions, as thieves may use exposed information to conduct targeted phishing attacks.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More California Breaches
Search all breaches reported in California