- State
- NY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 9,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR opened an investigation of the covered entity (CE), Counseling and Psychotherapy of Throggs Neck, after it reported that a password protected, unencrypted desktop computer was stolen which contained the protected health information (PHI) of 9,000 individuals. The PHI involved in the breach included names, addresses, dates of birth, social security numbers, diagnosis, patient notes and demographics. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE encrypted all of its patient databases and word processing programs on all computers. The CE improved physical safeguards by changing locks and fixing one of the entrance doors to the building to ensure that it automatically closes. The CE also placed security guards at all five entrances to the building and installed a video surveillance system. The CE also implemented internal safeguards and a policy to ensure that the last person in the office ensures rooms are vacant and the suite doors are locked upon leaving. As a result of OCR’s investigation the CE agreed to include effective dates and revision dates on its policies and to include documentation on the front page of its manual regarding annual reviews of the policies.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.