Back to the register

The Feinstein Institute for Medical Reserch

ArchivedSubmitted 09/14/2012
State
NY
Covered entity type
Healthcare Provider
Individuals affected
13,000
Business associate present
No
Type of breach
Theft
Location of breached information
Laptop
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Feinstein Institute for Medical Research (Feinstein) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). Feinstein will pay $3.9 million and will adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program; an effort it has already begun. Research institutions subject to HIPAA must be held to the same compliance standards as all other HIPAA-covered entities,” said OCR Director Jocelyn Samuels. “For individuals to trust in the research process and for patients to trust in those institutions, they must have some assurance that their information is kept private and secure.” Feinstein is a biomedical research institute that is organized as a New York not-for-profit corporation and is sponsored by Northwell Health, Inc., formerly known as North Shore Long Island Jewish Health System, a large health system headquartered in Manhasset, New York that is comprised of twenty one hospitals and over 450 patient facilities and physician practices. After receiving a breach notification from Feinstein involving unsecured electronic protected health information (ePHI), OCR initiated an investigation to ascertain the entity’s compliance with HIPAA Rules. OCR’s investigation indicated that the following occurred: • Feinstein impermissibly disclosed the ePHI of 13,000 individuals when an Feinstein-owned laptop computer containing ePHI was left unsecured in the back seat of an employee’s car; • Feinstein failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of the ePHI held by Feinstein, including the ePHI on the aforementioned laptop computer; • Feinstein failed to implement policies and procedures for granting access to ePHI by its workforce members; • Feinstein failed to implement physical safeguards for a laptop that contained ePHI to restrict access to unauthorized users; • Feinstein failed to implement policies and procedures that govern receipt and removal of hardware and electronic media that contain ePHI into and out of a facility, and the movement of these items within the facility; and, • Feinstein failed to implement a mechanism to encrypt ePHI or, alternatively, document why encryption was not reasonable and appropriate and implement an equivalent alternative measure to encryption to safeguard ePHI. The settlement requires Feinstein to establish a comprehensive compliance program designed to protect the security, confidentiality, and integrity of ePHI that includes: • A risk analysis and a risk management plan; • A process to evaluate and address any environmental or operational changes that affect the security of the ePHI it holds; • Policies and procedures to facilitate compliance with requirements of the HIPAA Rules; • A training program covering the requirements of the Privacy, Security, and Breach Notification Rules, intended to be used for all members of the workforce.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.