- State
- MA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 832
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Dr. Jeffrey Spiegel’s practice, the covered entity (CE), mistakenly sent a promotional email to approximately 500 patients with an attachment that included the email addresses of 832 patients. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE instituted a new procedure that requires two employees to proof promotional emails prior to sending. OCR obtained assurances that corrective actions listed above were completed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.