- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 10,000
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A workforce member of the covered entity (CE), Dent Neurologic Group, LLP erroneously sent an unencrypted email with a spreadsheet containing 10,202 patients’ protected health information (PHI) to the wrong patients. The types of PHI in the spreadsheet included patients’ names, addresses, active/former patient status, dates of last appointments, scheduling codes, and physicians’ names. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE implemented an email security appliance that encrypts emails and filters incoming messages for malware, viruses and spam as well as filter outgoing messages for identifiers. The CE also updated its email encryption policy and procedure, implemented its policy and procedure for encryption and password protection of electronic documents, and updated its training program for handling emails. Additionally, the CE sanctioned, counseled and retrained the workforce member. As a result of OCR’s investigation and technical assistance, the CE provided evidence of its remediation of Windows XP devices as well as an updated risk analysis to incorporate physical safeguards, penetration testing, and a corresponding Security Risk Assessment Report. The CE is expected to conduct a risk analysis that addresses all potential risks and vulnerabilities in the entire operation and to implement a risk management plan and corresponding risk mitigation activities.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.