- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,223
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Between January 1, 2015 and April 18, 2015, a physician employed by the covered entity (CE), Central Brooklyn Medical Group, PC, impermissibly disclosed the protected health information (PHI) of approximately 500 patients to his former medical assistants via facsimile on multiple occasions. On one occasion, the physician accidentally transposed digits in the intended facsimile number and disclosed the PHI of 88 patients to an unrelated third party. The types of PHI involved in the breach included patients’ names, ages, sex, appointment dates, times and reasons for visits, treating physician’s names, and medical conditions. The CE sent breach notification letters to 4,135 patients who had been scheduled to see the physician in the year prior to the breach because the CE could not identify which specific patients were affected; however, they were most likely within this group. The CE also provided breach notification to HHS and the media. Upon discovery of the breach, the CE confirmed the destruction of any PHI possessed by the unrelated third party and the medical assistant and sanctioned the physician. The CE also retrained its workforce members regarding HIPAA compliance, including the CE’s policy regarding communications via facsimile. OCR obtained assurances that the CE implemented the corrective actions listed above. In addition, the CE reported the physician to the State Office for Professional Medical Conduct.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.