Hospital for Special Surgery
bd_f98d219b1f51318c · schema v1 · pii pii-v1
Full breach record for Hospital for Special Surgery →3 incidents on fileHospital for Special Surgery (NY) reported to HHS OCR on 2016-03-17 an Unauthorized Access/Disclosure affecting 647 individuals. An employee sent an email to research study participants without using BCC, inadvertently revealing each participant's email address and general research study information to other recipients. The ePHI was transmitted via email. No business associate was involved. Following the breach, the employee received one-on-one HIPAA training, and the CE committed to revising its email policy and increasing HIPAA training frequency to at least three times per year.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Mar 17, 2016
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.