BryLin Hospitals, Inc. (NY) reported an email phishing attack in which an employee fell victim, exposing ePHI of approximately 8,000 individuals. Compromised data included names, dates of birth, Social Security numbers, and treatment information. The hospital notified HHS, affected individuals, and the media, provided substitute notice, and implemented additional administrative and technical safeguards.
Affected (this filing): 8,000