East End Disability Associates
Disclosed Nov 20, 20187 years ago896 affectedConfirmed
East End Disability Associates, Inc., the covered entity (CE), discovered that a hacker compromised five employee email accounts and caused emails to be automatically forwarded to an external email address. The hacker may have accessed the full names, birthdates, addresses, account and identification numbers, diagnoses, and treatment information of 896 individuals. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE investigated and removed auto-forwarding rules and global administrative rights from the affected email accounts and reviewed other user accounts to confirm that forwarding rules had not been applied. The CE implemented additional technical safeguards including two-factor authentication for access to email accounts and computer login. The CE revised its policies and procedures regarding internal sharing of PHI and trained staff on the revised policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed above. In addition, the CE is expected to develop and implement a risk management plan that addresses the process for managing and reducing the risks identified in the risk
What is known
| People affected | 896 (as reported to HHS) |
|---|---|
| Disclosed | Nov 20, 2018 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): East End Disability Associates (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 20, 2018 | 896 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.