- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 500
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Cromwell Fire District, the covered entity (CE), filed a breach report stating that a door to a storage room containing ambulance run reports was left propped open for approximately two hours. The OCR investigation revealed that the CE did not have policies and procedures in place at the time of the incident to conduct a breach risk assessment and had not conducted a breach risk assessment prior to filing the breach report with OCR. OCR provided technical assistance to the CE regarding conducting a breach risk assessment, breach notification requirements, and other provisions in the Privacy Rule. As a result of OCR’s investigation, the CE conducted a breach risk assessment and determined there was a low probability that the protected health information has been compromised based on the following factors: that the building received few visitors and was not known to have received a visitor during that time period, that the ambulance run reports appeared undisturbed, and that the situation was mitigated (the door was closed and locked) as soon as it was discovered. Thereafter, the CE determined that a breach had not occurred. In addition, as a result of OCR’s investigation, the CE revised and adopted additional policies and procedures, and implemented a new template business associate agreement.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.