- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 913
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity's (CE) former Chief Information Officer instructed a former Assistant IT Director to copy files containing the protected health information (PHI) of 913 clients onto a portable computer drive. Subsequently, the former CIO took the drive with him to his new employer after he was terminated. The types of PHI involved in the breach included names, addresses, dates of birth, social security numbers, Medicaid numbers and diagnoses The CE provided breach notification to HHS, the affected individuals, and the media. As a result of OCR’s investigation, the CE revised its procedures with respect to assigning an approval process for access to removable media. In addition, the CE conducted a risk analysis and established a risk management plan to manage and reduce the risks identified in the risk analysis, including, but not limited to, access to removable drives. As a result of OCR's investigation it is expected to implement technical security measures to guard against unauthorized access to ePHI, and review and revise its policies and procedures and training materials regarding the Security Rule. Additionally, the CE is expected to execute HIPAA-compliant business associate agreements with all existing business associates by September 1, 2017.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.