Back to the register

Diamond Institute for Fertility and Menopause, LLC

ArchivedSubmitted 04/28/2017
State
NJ
Covered entity type
Healthcare Provider
Individuals affected
14,633
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On February 27, 2017, Diamond Institute for Fertility and Menopause LLC, the covered entity (CE), discovered that an unknown individual with a foreign internet address used a doctor’s login credentials to gain access to a computer server containing the electronic protected health information (ePHI) of patients. The breach affected 14,633 individuals and the types of ePHI involved included demographic information, lab results, and social security numbers. The CE provided timely breach notification to HHS, affected individuals, and the media. In response to the breach, the CE disabled the compromised account, forced the intruder off its systems, purchased a new firewall, replaced the server and several workstations, and improved password protocols. The CE terminated its business associate (BA) responsible for safeguarding its ePHI and hired a new BA. OCR obtained assurances that the CE implemented the corrective actions listed. In addition to the corrective actions completed, the CE is expected to perform a risk analysis, establish a risk management plan, document the unauthorized disclosure of its patients’ ePHI for accounting of disclosure purposes, execute agreements with BAs, perform a technical and non-technical evaluation in response to environmental or operational changes, and implement access controls and valid encryption processes. The CE is also expected to develop policies and procedures and train all of its workforce members regarding the Breach Notification Rule’s requirements.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.