New York State Office of Mental Health
bd_1907c6633388f019 · schema v1 · pii pii-v1
Full breach record for New York State Office of Mental Health →New York State Office of Mental Health (NY) reported to HHS OCR on 2015-04-10 a Loss affecting 563 individuals. A workforce member lost an unencrypted (password-protected) laptop in a New York City taxicab. The device contained PHI of research participants at the Nathan S. Kline Institute for Psychiatric Research, including names, phone numbers, ages/birthdates, and coded diagnostic/assessment data. No business associate was involved. The CE notified HHS, media, and affected individuals, offered identity protection services, and implemented encryption, network access controls, and policy reforms. OCR obtained assurances of corrective action.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 10, 2015
- Raw hash
- 1c842341286a8f7520cd9b080c670ada4cdbe6f13a788e4866c4e286a0ce8efd
Source filing
Reporting entity
- Name
- New York State Office of Mental Healthnorm: new york state office of mental health
- Industry
- Health Care Services
Victim entity
- Name
- New York State Office of Mental Healthnorm: new york state office of mental health
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 563
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Internal
- Regulator citations
- Notified HHS OCR of the breachOCR obtained assurances that the CE implemented corrective actionsOCR stated expectation that CE conduct a risk analysis, implement a remediation plan, and ensure implementation of policies and procedures relating to asset and inventory management, access and audit controls, secure storage, data loss prevention and secure configuration controls
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.