Back to the register

Mount Sinai Beth Israel

ArchivedSubmitted 10/03/2014
State
NY
Covered entity type
Healthcare Provider
Individuals affected
10,793
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Mount Sinai Beth Israel, the covered entity (the CE), reported the theft of an unencrypted laptop computer containing the protected health information (PHI) of 10,793 patients from the Department of Obstetrics/Gynecology on-call room. The PHI consisted of demographic and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE reported the theft to law enforcement, remotely changed the password on the stolen laptop, enhanced physical safeguards and retrained staff on privacy and security issues related to data security and encryption. During the investigation, OCR obtained assurances that the CE implemented the corrective actions. As a result of the investigation, the CE is expected to implement a corresponding risk management and remediation plan as identified in its risk analysis. The CE is expected to implement a comprehensive policy and procedure for personally owned devices that have access to the CE’s electronic PHI to ensure that they are encrypted, tracked and monitored for encryption.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.