Back to the register

Mount Sinai Medical Center

ArchivedSubmitted 10/21/2013
State
NY
Covered entity type
Healthcare Provider
Individuals affected
610
Business associate present
No
Type of breach
Loss
Location of breached information
Other Portable Electronic Device
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Mount Sinai Medical Center, reported that a provider’s personal unencrypted portable computer drive (a universal serial bus (USB) drive) was lost or stolen from the CE. The USB drive contained the protected health information (PHI) of 610 individuals and included names, dates of birth, medical record numbers, procedure logs, procedure dates, procedure information, and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE sanctioned the provider, reminded all workforce members of its guidance and resources for encryption, and retrained all workforce members on HIPAA privacy and security. As a result of OCR’s investigation, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and implement workstation security. The CE is expected to update and clarify its policies for portable devices and device and media controls and review its HIPAA training content. The CE is also expected to implement a comprehensive policy and procedure for personally owned electronic devices to ensure that they are encrypted, tracked and monitored for encryption.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.