Back to the register

Memorial Sloan-Kettering Cancer Center

ArchivedSubmitted 11/13/2013
State
NY
Covered entity type
Healthcare Provider
Individuals affected
2,279
Business associate present
No
Type of breach
Loss
Location of breached information
Other Portable Electronic Device
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Memorial Sloan Kettering Cancer Center, the covered entity (CE), reported that a former employee’s personal unencrypted external computer hard drive was lost or stolen. The drive contained the protected health information (PHI) of 2,279 of the CE’s patients and included names, addresses, telephone numbers, dates of birth, medical record numbers, physician names, appointment dates, procedure type, and clinical information. The CE notified HHS, the media, and the affected individuals. Following the breach, the CE obtained assurances from the employee and his current employer that the PHI was deleted from all devices, computers and servers. The CE purchased and implemented an encryption solution to encrypt all data copied from its workstations, USB and external drives. The CE retrained employees on its HIPAA policies and procedures and reinforced its policies prohibiting the use of personal portable electronic data storage devices. During the investigation, OCR obtained assurances that the CE implemented the corrective actions. The CE is expected to conduct a risk analysis and implement a corresponding risk management plan.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.