- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 946
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Four Middlesex Hospital employees responded to a phishing email, resulting in the disclosure of the protected health information (PHI) of 945 individuals. The information accessed included patients’ names, addresses, dates of birth and social security numbers. The covered entity (CE), provided breach notification to HHS, affected individuals, and the media. The CE also set up a dedicated call center to answer questions for affected individuals and provided affected individuals with 12 months of credit monitoring services at no cost. Following the breach, the CE developed a mandatory Phishing Awareness and Response Training program for employees and required additional training for all supervisors and managers to provide to their staff. Additional mitigation included the designation of March as “Cyber Awareness” month, which includes the implementation of a number of tools to educate staff on cyber threats, separate personal meetings and trainings between those employees whose accounts had been compromised, and the procurement of a vendor to conduct social engineering testing to assess the effectiveness of the CE's staff training. The CE also upgraded its anti-virus program and will continue to utilize the security reporting tool it had purchased, which detected this breach. OCR obtained assurances that the CE implemented the corrective action steps listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.