Back to the register

Mount Sinai Hospital

ArchivedSubmitted 08/02/2019
State
NY
Covered entity type
Healthcare Provider
Individuals affected
33,730
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Mount Sinai Hospital, reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency (AMCA), was the victim of a cyber-attack involving the electronic protected health information (ePHI) of 33,730 individuals. The ePHI involved included names, dates of service, clinical information, and health insurance information. The CE notified HHS, affected individuals, and the media. OCR’s investigation resulted in the CE implementing additional administrative safeguards to better protect its sensitive data. As a consequence of this breach incident, the CE terminated its relationship with the BA.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.