NEW YORKMisuseHealthcareHealthcarePrivilege AbuseKnowledge AbuseCustomer Data InvolvedData ExfiltratedTargetedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
MONTEFIORE MEDICAL CENTER
bd_a87192afde76d3d2 · schema v1 · pii pii-v1
Full breach record for MONTEFIORE MEDICAL CENTER →Montefiore Medical Center (NYC non-profit hospital system) reported to HHS OCR on 2015-07-22 a Theft breach affecting 12,517 individuals. An employee stole ePHI from electronic medical records approximately two years prior (c. 2013) and sold it to an identity theft ring over a ~6-month period. NYPD notified Montefiore in May 2015. HHS OCR investigation resulted in a $4.75 million settlement and a corrective action plan. No business associate was involved.
HIPAA clockDiscovered May 1, 2015 → Notified Jul 22, 201582d ✗ HIPAA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12,517 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 22, 2015
- Raw hash
- 4442b8e3737cca1d93551e580e522ac927ae538ab7d50c530c97d4c556d6bc2c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- MONTEFIORE MEDICAL CENTERnorm: montefiore medical center
- Domain
- montefiore.org
- Industry
- Health Care Services
Victim entity
- Name
- MONTEFIORE MEDICAL CENTERnorm: montefiore medical center
- Domain
- montefiore.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- May 1, 2015
- Materiality determined
- —
- Notification sent
- Jul 22, 2015
- Affected individuals
- 12,517
- Data types
- HEALTH_BASICIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1052 Exfiltration Over Physical Medium
- Threat actor
- InternalFinancial
- Regulator citations
- HHS OCR settlement: $4,750,000 monetary penaltyCorrective action plan implementedOCR monitoring period: 2 years
- Initial access
- insider_action
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 82dHHS notified · 82d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: May 1, 2015→ Notified: Jul 22, 201582d 60 days HIPAA 60-day late HIPAA Discovered: May 1, 2015→ Notified: Jul 22, 201582d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.