Brookdale Hospital and Medical Center
Disclosed Jul 20, 201313 years ago2,700 affectedConfirmed
The covered entity (CE), Brookdale Hospital and Medical Center, reported a breach when a staff pharmacist lost an unencrypted USB external hard drive that contained the electronic protected health information (ePHI) of 2,700 patients. The ePHI included addresses, zip codes, dates of birth, diagnosis codes, and medical record numbers. The CE provided breach notification to HHS, the affected individuals, and the media. Following the loss, the CE disabled all USB ports in all of its computers to prevent any staff members from using USB external hard drives to store data from its electronic records system, established a policy on obtaining an encrypted USB external hard drive from its IT department, and retrained its pharmacist staff. As a result of OCR’s investigation and technical assistance, the CE is expected to review and revise its policies and procedures and training materials regarding reporting breach incidents and the usage of mobile and portable devices by its staff members. Additionally, OCR stated the expectation that the CE will perform a thorough and accurate enterprise wide risk analysis and establish a Risk Management Plan that addresses the threats and vulnerabilities
What is known
| People affected | 2,700 (as reported to HHS) |
|---|---|
| Disclosed | Jul 20, 2013 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Brookdale Hospital and Medical Center (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 20, 2013 | 2,700 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.