Day Kimball Healthcare
Disclosed Oct 22, 20187 years ago698 affectedConfirmed
OCR opened an investigation of the covered entity (CE), Day Kimball Healthcare, after it filed a breach report stating that two former employees impermissibly used protected health information (PHI) to send solicitation letters to patients for their new place of employment. The potential size of the breach was 698 individuals and the types of PHI included names, addresses, phone numbers, marital status, providers, and appointment history. Following the breach, the CE immediately conducted a risk assessment and an audit of the former employees’ access. The CE contacted the new employer and requested they destroy or return any PHI and cease using it for inappropriate purposes. The CE provided breach notification to affected individuals, offered two years of identity protection services, and established a dedicated call center to respond to breach inquiries. As a result of OCR’s investigation, the CE provided updated copies of policies and procedures regarding breach notification, use and disclosures of PHI, and safeguarding PHI.
What is known
| People affected | 698 (as reported to HHS) |
|---|---|
| Disclosed | Oct 22, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Day Kimball Healthcare (Healthcare Provider, CT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 22, 2018 | 698 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.