- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,775
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer, Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized party accessed the covered entity’s (CE) electronic medical record (EMR) system containing the protected health information (PHI) of 3,775 patients. The CE reported that the PHI consisted of names, addresses, dates of birth, medical history, diagnosis/conditions, lab/test results, treatment information, medications, health insurance information, claims information and Medicare ID numbers, which is also a Medicare patient’s Social Security number. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE uninstalled and deleted the remote access software used to access its EMR program and installed a new EMR system after the CE replaced the impacted computer. The CE implemented additional safeguards such as strengthening passwords and ensuring that all systems and programs are updated by utilizing available patches and updates. As result of the breach, the CE provided the affected individuals one year of free credit monitoring. OCR obtained assurances that the CE implemented the corrective actions listed above. The CE is expected to conduct a risk analysis and implement a corresponding remediation plan. The CE is also expected to implement policies and procedures regarding security Incidents, access controls, audit controls, transmission security, periodic system review, uses and disclosures of PHI, and safeguards. Additionally, the CE is expected to implement procedures to regularly review records of information system activity and ensure on-going security awareness training.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.