BST & Co. CPAs
Disclosed Feb 16, 20206 years ago170,000 affectedConfirmed
Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (“BST”), a New York public accounting, business advisory, and management consulting firm, concerning a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. BST is a HIPAA business associate and receives financial information that also contains protected health information (PHI) from a HIPAA covered entity. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates – such as BST – must follow to protect the privacy and security of PHI. The HIPAA Security Rule establishes national standards to protect and secure our health care system by requiring administrative, physical, and technical safeguards to ensure the confidentiality, integrity, availability, and security of electronic protected health information (ePHI). The Risk Analysis provision requires regulated organizations (covered entities and business associates) to con
What is known
| People affected | 170,000 (as reported to HHS) |
|---|---|
| Disclosed | Feb 16, 2020 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): BST & Co. CPAs (Business Associate, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 16, 2020 | 170,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.