Back to the register

Stamford Health

ArchivedSubmitted 04/30/2020
State
CT
Covered entity type
Healthcare Provider
Individuals affected
1,255
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Stamford Health, the covered entity (CE), reported that an employee impermissibly disclosed the electronic protected health information (ePHI) of 1,255 individuals when an email was sent without masking the email addresses of recipients. The ePHI involved included email addresses and treatment information. The CE notified HHS, affected individuals, and the media. As a result of this breach, Stamford Health implemented additional technological safeguards, updated its related policies and procedures, and provided relevant workforce training.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.