Skip to content

BST & Co. CPAs

Disclosed Feb 16, 20206 years ago170,000 affectedConfirmed

Official notice

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (“BST”), a New York public accounting, business advisory, and management consulting firm, concerning a potential violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. BST is a HIPAA business associate and receives financial information that also contains protected health information (PHI) from a HIPAA covered entity. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates – such as BST – must follow to protect the privacy and security of PHI. The HIPAA Security Rule establishes national standards to protect and secure our health care system by requiring administrative, physical, and technical safeguards to ensure the confidentiality, integrity, availability, and security of electronic protected health information (ePHI). The Risk Analysis provision requires regulated organizations (covered entities and business associates) to con

What is known

People affected170,000 (as reported to HHS)
DisclosedFeb 16, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): BST & Co. CPAs (Business Associate, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 16, 2020170,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about BST & Co. CPAs

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.