- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 698
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR opened an investigation of the covered entity (CE), Day Kimball Healthcare, after it filed a breach report stating that two former employees impermissibly used protected health information (PHI) to send solicitation letters to patients for their new place of employment. The potential size of the breach was 698 individuals and the types of PHI included names, addresses, phone numbers, marital status, providers, and appointment history. Following the breach, the CE immediately conducted a risk assessment and an audit of the former employees’ access. The CE contacted the new employer and requested they destroy or return any PHI and cease using it for inappropriate purposes. The CE provided breach notification to affected individuals, offered two years of identity protection services, and established a dedicated call center to respond to breach inquiries. As a result of OCR’s investigation, the CE provided updated copies of policies and procedures regarding breach notification, use and disclosures of PHI, and safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.