Back to the register

New York State Office of Mental Health

ArchivedSubmitted 04/10/2015
State
NY
Covered entity type
Healthcare Provider
Individuals affected
563
Business associate present
No
Type of breach
Loss
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), the New York State Office of Mental Health, reported a breach when a workforce member lost her password-protected, but unencrypted, laptop computer in a New York City taxicab. The CE reported the laptop contained the protected health information of 563 participants in certain research studies at the CE’s Nathan S. Kline Institute for Psychiatric Research (NKI). The PHI consisted of names, phone numbers, ages or birthdates, and in some cases, coded diagnostic information, data obtained from assessments/tests and/or an informational note. The CE notified HHS, the media, and the affected individuals (including the offer of one year of identity protection services at no cost). Following the breach, the CE replaced all devices found to be out of compliance with current encryption standards, and implemented a network access control device to guarantee that unencrypted devices, and devices sourced from outside of the CE will no longer work on the NKI network. The CE also required investigators to submit more detailed data security plans to the Institutional Review Board, and restricted NKI researchers from downloading data from a specific research database without prior approval from a manager. The CE also sanctioned the workforce member in connection with the breach incident. During the course of the investigation, OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, OCR stated the expectation that the CE will conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to asset and inventory management, access and audit controls, secure storage, data loss prevention and secure configuration controls.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.