NYU Langone Hospitals
ent_019e0a5b4ead57753488324d5ef9a455
Disclosures
4
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
44,009
nationwide · HHS OCR NY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- NYU Langone Hospitals
- Normalized
- nyu langone hospitals— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900A1087KNNZSNH72
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- nyulangone.org
Disclosure history (4)newest first
- NEW YORKHHS OCRas victim2022-01-06
NYU Langone Hospitals reported to HHS on 2022-01-06 an Unauthorized Access/Disclosure affecting 1,141 individuals. An affiliated practice mailed PHI to the wrong recipients; the letters contained only the names of intended recipients. Breached information was located on Paper/Films. The entity notified HHS, affected individuals, the media, and posted substitute notice online. The affiliated practice subsequently strengthened its administrative safeguards.
- NEW YORKHHS OCRas victim2020-10-30
NYU Langone Hospitals reported to HHS on 2020-10-30 a Hacking/IT Incident affecting 44009 individuals. Breached information located on Network Server. A business associate experienced a ransomware attack affecting ePHI including names, addresses, dates of birth, and treatment information. The CE notified HHS, affected individuals, and the media.
- NEW YORKHHS OCRas victim2014-06-20
NYU Hospitals Center reported to HHS on 2014-06-20 a Theft affecting 872 individuals. An employee's unencrypted laptop was stolen, containing ePHI including names, addresses, birthdates, clinical information, and medications prescribed. The covered entity implemented additional administrative safeguards as part of its mitigation efforts. Breached information was located on a Laptop. No business associate was involved.
- NEW YORKHHS OCRas victim2010-07-07
NYU Hospitals Center (NY) reported to HHS OCR on 2010-07-07 that an unencrypted USB drive containing ePHI of 2,563 individuals was misplaced (reported internally as a possible theft). The ePHI included names, medical record numbers, ages, genders, procedures, physician names, anesthesia types, and recovery room timestamps. Following OCR's investigation, the CE halted unencrypted USB use, installed DLP software, updated physical security, purchased encrypted USB drives, revised its mobile device policy, and retrained all workforce members. Breached information located on Other Portable Electronic Device.