DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

For NYC Health & Hospitals Corporation, 2011 wasn't a great year for data security, Part 1

Posted on November 10, 2014 by Dissent

It seems that 2011 was not exactly a stellar year for the NYC Health & Hospitals Corporation (“HHC”) for data security.

The first HHC incident was the 2011 breach involving the theft of backup tapes with information on 1.7 million patients. HHC did not incur any monetary penalties for that breach.

The second incident, not previously known to this site, also occurred in 2011, but was only added to HHS’s database this past week.

HHS’s log entry for the incident looks like this:

New York City Health & Hospitals Corporation,NY,””,10058,07/01/2011,Unauthorized Access/Disclosure,Paper,11/07/2014,

So why is a breach that impacted over 10,000 patients in 2011 first showing up now in HHS’s database? It turns out that the answer is that HHC only first discovered the breach in August of this year and only first notified patients in October of this year.

A statement posted October 10, 2014 on HHC’s website reads:

The New York City Health and Hospitals Corporation (HHC) this week began to notify 10,058 patients who received services at four now-closed clinics in Brooklyn about the possible disclosure of some of their personal or protected health information (PHI) when records were improperly stored in boxes in an enclosed employee parking garage at the East New York Diagnostic and Treatment Center. A sample notification to the affected patients at (1) the Howard Houses Child Health Center; (2) the Brevoort Houses Child Health Clinic; (3) the Fifth Avenue Child Health Clinic and (4) the Brownsville Child Health Clinic is attached.

There is no evidence to suggest that the files were accessible to the general public or that the protected health information in the files has, in fact, had been improperly accessed by any person or entity. Nonetheless, the records were stored in a manner that HHC staff without authority to access such records could have accessed them.

In an abundance of caution, HHC has taken decisive steps to protect the individuals who are potentially affected, by immediately securing and removing the boxes of records and properly storing them, and timely notifying the required federal oversight agency.

HHC, through third party vendor AllClear ID, Inc. is offering free credit monitoring and identity protection services for one year to those patients whose medical records were stored in the garage. HHC has also set up a toll-free hotline, 1-866-979-2599, to provide additional information. Notifications will also be posted on the HHC website and will be distributed to numerous New York area news outlets.

Personal health information can include name, address, diagnosis, medications, treatment regimen, medical record number, and social security number.

HHC has taken immediate measures to prevent a reoccurrence of this incident by increasing the number of security and privacy walk-throughs it conducts at its facilities and by ensuring that the HHC workforce is reminded of the importance of managing PHI in a safe and secure manner and of reporting any incidents where that is not the case.

So that was their second incident in 2011. But it turns out there was third incident. Follow me to the next post.

Related posts:

  • Operation Anti Security Breakdown and targets, the full time line
  • NY: Jacobi Medical Center notifies 90,060 patients after employee emailed PHI to her personal account and new email address at another employer
  • HHC Press release on backup tapes stolen from GRM van
  • For NYC Health & Hospitals Corporation, 2011 wasn't a great year for data security, Part 2
Category: Uncategorized

Post navigation

← Terminated employee continued to access Bon Secours' patients' billing information
For NYC Health & Hospitals Corporation, 2011 wasn't a great year for data security, Part 2 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Mississippi Law Firm Sues Cyber Insurer Over Coverage for Scam
  • Ukrainian Hackers Wipe 47TB of Data from Top Russian Military Drone Supplier
  • Computer Whiz Gets Suspended Sentence over 2019 Revenue Agency Data Breach
  • Ministry of Defence data breach timeline
  • Hackers Can Remotely Trigger the Brakes on American Trains and the Problem Has Been Ignored for Years
  • Ransomware in Italy, strike at the Diskstation gang: hacker group leader arrested in Milan
  • A year after cyber attack, Columbus could invest $23M in cybersecurity upgrades
  • Gravity Forms Breach Hits 1M WordPress Sites
  • Stormous claims to have protected health info on 600,000 patients of North Country Healthcare. The patient data appears fake. (2)
  • Back from the Brink: District Court Clears Air Regarding Individualized Damages Assessment in Data Breach Cases

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The EU’s Plan To Ban Private Messaging Could Have a Global Impact (Plus: What To Do About It)
  • A Balancing Act: Privacy Issues And Responding to A Federal Subpoena Investigating Transgender Care
  • Here’s What a Reproductive Police State Looks Like
  • Meta investors, Zuckerberg to square off at $8 billion trial over alleged privacy violations
  • Australian law is now clearer about clinicians’ discretion to tell our patients’ relatives about their genetic risk
  • The ICO’s AI and biometrics strategy
  • Trump Border Czar Boasts ICE Can ‘Briefly Detain’ People Based On ‘Physical Appearance’

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.