Mary Hitchcock Memorial Hospital d/b/a Dartmouth-Hitchcock Medical Center Data Breach
Dartmouth-Hitchcock: 1,201 Patients Affected by Lost Laptop
What happened in the Mary Hitchcock Memorial Hospital d/b/a Dartmouth-Hitchcock Medical Center data breach?
The Mary Hitchcock Memorial Hospital d/b/a Dartmouth-Hitchcock Medical Center data breach was reported on July 15, 2022 and affected 1,201 individuals. The breach type was Loss involving Laptop. This breach occurred in New Hampshire. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Mary Hitchcock Memorial Hospital d/b/a Dartmouth-Hitchcock Medical Center Breach Details
Dartmouth-Hitchcock Medical Center Data Breach Report
Opening Summary
Mary Hitchcock Memorial Hospital, operating as Dartmouth-Hitchcock Medical Center in New Hampshire, experienced a data breach involving the loss of a laptop computer on an unspecified date prior to July 15, 2022, when the breach was formally reported to state authorities. The loss of the portable computing device resulted in potential unauthorized access to protected health information (PHI) belonging to approximately 1,201 patients. As a major academic medical center serving a multi-state region in northern New England, this incident represents a significant privacy event requiring comprehensive notification and remediation efforts.
Discovery and Response Timeline
The breach was discovered through standard asset management and inventory procedures, likely when the laptop was reported missing or when its absence was noted during routine audits. Upon discovery, Dartmouth-Hitchcock Medical Center initiated an investigation to determine what data may have been stored on the device and assess the risk to affected individuals. The organization notified the New Hampshire Attorney General's office and submitted formal breach notification documentation on July 15, 2022, in compliance with state breach notification laws. The hospital subsequently began the process of notifying affected patients of the potential exposure, providing them with information about the breach and recommended protective measures. The response timeline indicates the organization followed established incident response protocols, though the specific lag between discovery and notification submission is not detailed in available records.
Breach Mechanics and Technical Context
The loss of a laptop computer represents a physical security breach rather than a cyber-attack or network intrusion. Laptops are particularly vulnerable devices in healthcare settings because they are portable, frequently transported between locations, and often contain cached or stored copies of patient data for clinical workflow purposes. Unlike network-based breaches that may be detected through system monitoring and intrusion detection systems, the loss of a physical device may go unnoticed for extended periods depending on organizational asset tracking procedures. The device may have contained unencrypted patient data, clinical notes, appointment information, or other PHI either in active files or in temporary cache files. Without confirmation of encryption status or data sanitization protocols, the breach must be treated as a potential full exposure of any data that was present on the device at the time of loss. The risk of unauthorized access depends on whether the device was password-protected, whether the operating system employed full-disk encryption, and whether the finder or thief possessed technical knowledge to bypass security controls.
Organizational Context
Dartmouth-Hitchcock Medical Center is a major academic medical center affiliated with the Geisel School of Medicine at Dartmouth College, serving as the primary teaching hospital for the region. The organization operates multiple facilities across New Hampshire and Vermont, providing comprehensive inpatient, outpatient, emergency, and specialty care services. As an academic medical center, the institution maintains extensive electronic health records systems and conducts clinical research, both of which generate and store significant volumes of patient data. The organization's size and complexity, combined with the mobile nature of clinical work in academic settings, creates inherent challenges in maintaining physical security over all computing devices. The breach affects a relatively small percentage of the organization's total patient population, suggesting the lost laptop may have belonged to a specific department, clinical unit, or individual provider rather than representing a system-wide data exposure.
Patient Impact and Notification
Approximately 1,201 individuals were notified of the potential breach of their protected health information. These patients may have had various types of PHI exposed depending on the laptop's usage and the data stored on it. Typical information that may have been present on a clinical laptop could include names, dates of birth, medical record numbers, insurance information, diagnoses, treatment plans, medication lists, and clinical notes. The notification process, required under New Hampshire's breach notification statute and HIPAA's Breach Notification Rule, informed affected patients of the incident, the types of information potentially exposed, and recommended actions to protect themselves. Patients were advised to monitor their accounts for suspicious activity and to consider credit monitoring services. The hospital likely offered a period of complimentary credit monitoring or identity theft protection services as part of its remediation efforts, a standard practice following breaches involving sensitive personal information.
HIPAA and Regulatory Context
Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities like Dartmouth-Hitchcock Medical Center are required to implement administrative, physical, and technical safeguards to protect patient privacy and security. The loss of a laptop containing unencrypted PHI may indicate a gap in physical safeguards, such as inadequate device tracking, insufficient encryption requirements, or insufficient policies regarding the storage of sensitive data on portable devices. HIPAA's Security Rule requires that covered entities implement encryption for data in transit and at rest, particularly for portable devices that are at higher risk of loss or theft. The breach notification requirement mandates that covered entities notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. Dartmouth-Hitchcock's submission to state authorities on July 15, 2022, demonstrates compliance with these notification requirements. The incident may trigger a corrective action plan requiring the organization to strengthen its device management policies, implement mandatory encryption for all portable devices, enhance asset tracking procedures, and provide additional staff training on data security and device handling protocols.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Mary Hitchcock Memorial Hospital d/b/a Dartmouth-Hitchcock Medical Center Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries, and consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review medical bills and explanation of benefits statements carefully for any services or charges that were not received, and contact your healthcare providers and insurance company immediately if you identify suspicious activity
Change passwords for any online healthcare portals, insurance accounts, and financial accounts, using strong, unique passwords that are not reused across multiple platforms
Consider enrolling in the complimentary credit monitoring and identity theft protection services offered by Dartmouth-Hitchcock Medical Center, which typically provide 12-24 months of monitoring and fraud resolution assistance
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New Hampshire Breaches
Search all breaches reported in New Hampshire