- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,700
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Brookdale Hospital and Medical Center, reported a breach when a staff pharmacist lost an unencrypted USB external hard drive that contained the electronic protected health information (ePHI) of 2,700 patients. The ePHI included addresses, zip codes, dates of birth, diagnosis codes, and medical record numbers. The CE provided breach notification to HHS, the affected individuals, and the media. Following the loss, the CE disabled all USB ports in all of its computers to prevent any staff members from using USB external hard drives to store data from its electronic records system, established a policy on obtaining an encrypted USB external hard drive from its IT department, and retrained its pharmacist staff. As a result of OCR’s investigation and technical assistance, the CE is expected to review and revise its policies and procedures and training materials regarding reporting breach incidents and the usage of mobile and portable devices by its staff members. Additionally, OCR stated the expectation that the CE will perform a thorough and accurate enterprise wide risk analysis and establish a Risk Management Plan that addresses the threats and vulnerabilities identified by the risk analysis.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.