- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,278
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 13, 2017, an unknown individual accessed the covered entity's (CE) CEO’s email account and sent emails to its employees. The CEO’s email account contained a file with the electronic protected health information (ePHI) – names and client numbers – of approximately 1,273 individuals. The CE immediately took steps to implement additional technical safeguards for its email system and engaged a third-party service to assist in its ongoing privacy and security activities. The CE provided breach notification to HHS, and OCR provided technical assistance regarding the breach notification requirements pertaining to to the media and affected individuals.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.