- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 610
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Mount Sinai Medical Center, reported that a provider’s personal unencrypted portable computer drive (a universal serial bus (USB) drive) was lost or stolen from the CE. The USB drive contained the protected health information (PHI) of 610 individuals and included names, dates of birth, medical record numbers, procedure logs, procedure dates, procedure information, and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE sanctioned the provider, reminded all workforce members of its guidance and resources for encryption, and retrained all workforce members on HIPAA privacy and security. As a result of OCR’s investigation, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and implement workstation security. The CE is expected to update and clarify its policies for portable devices and device and media controls and review its HIPAA training content. The CE is also expected to implement a comprehensive policy and procedure for personally owned electronic devices to ensure that they are encrypted, tracked and monitored for encryption.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.