- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 63,551
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A misconfigured radiology interface application permitted unauthorized individuals to access 63,551 patients’ electronic protected health information (ePHI). The ePHI affected by this incident included patients’ names, dates of birth, client identification numbers, dates of service, and, for approximately 250 patients, radiology reports and images. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE secured the radiology application so that only authorized staff could access it, amended its policies and procedures to require that all systems and their security settings be tested in a test environment prior to live deployment, and trained relevant workforce members regarding this policy change. The CE also sanctioned the workforce member responsible for this incident. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to perform a risk analysis and establish a risk management plan, and document the unauthorized disclosure of its patients’ ePHI for accounting of disclosure purposes. Also, the CE is expected to perform a technical and non-technical evaluation in response to environmental or operational changes, regularly review records of activity in all information systems, implement procedures for monitoring log-in attempts, and implement audit controls and valid encryption processes.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.