Back to the register

Day Kimball Healthcare

ArchivedSubmitted 10/22/2018
State
CT
Covered entity type
Healthcare Provider
Individuals affected
698
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR opened an investigation of the covered entity (CE), Day Kimball Healthcare, after it filed a breach report stating that two former employees impermissibly used protected health information (PHI) to send solicitation letters to patients for their new place of employment. The potential size of the breach was 698 individuals and the types of PHI included names, addresses, phone numbers, marital status, providers, and appointment history. Following the breach, the CE immediately conducted a risk assessment and an audit of the former employees’ access. The CE contacted the new employer and requested they destroy or return any PHI and cease using it for inappropriate purposes. The CE provided breach notification to affected individuals, offered two years of identity protection services, and established a dedicated call center to respond to breach inquiries. As a result of OCR’s investigation, the CE provided updated copies of policies and procedures regarding breach notification, use and disclosures of PHI, and safeguarding PHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.