Bronx Lebanon Hospital Center
Disclosed Oct 25, 201312 years ago10,930 affectedConfirmed
A transcription company’s subcontractor misconfigured its server, such that search engines, such as Google, were able to locate the server and index the records on that machine, including names, dates of service, medical record number, dates of birth and types of procedures/diagnoses for patients of the covered entity (CE), Bronx Lebanon Hospital Center. The CE that had retained the transcription company, Professional Transaction Services (PTC), provided breach notification to HHS, affected individuals, and the media. Once the CE learned of the breach, it initiated an investigation and learned that PTC’s subcontractor immediately disabled the server, destroyed the hard drive that stored the PHI, and worked with Google to remove the protected health information (PHI) from the Google caches. The CE also engaged a technical consultant to conduct forensic analyses and work to ensure that affected patients’ records could no longer be found by commonly used internet search engines. The CE also terminated its relationship with PTC and engaged a new transcription company. OCR obtained assurances that the CE implemented the corrective actions listed.
What is known
| People affected | 10,930 (as reported to HHS) |
|---|---|
| Disclosed | Oct 25, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Bronx Lebanon Hospital Center (Business Associate, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 25, 2013 | 10,930 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.