- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 896
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
East End Disability Associates, Inc., the covered entity (CE), discovered that a hacker compromised five employee email accounts and caused emails to be automatically forwarded to an external email address. The hacker may have accessed the full names, birthdates, addresses, account and identification numbers, diagnoses, and treatment information of 896 individuals. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE investigated and removed auto-forwarding rules and global administrative rights from the affected email accounts and reviewed other user accounts to confirm that forwarding rules had not been applied. The CE implemented additional technical safeguards including two-factor authentication for access to email accounts and computer login. The CE revised its policies and procedures regarding internal sharing of PHI and trained staff on the revised policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above. In addition, the CE is expected to develop and implement a risk management plan that addresses the process for managing and reducing the risks identified in the risk analysis to a reasonable and appropriate level.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.