ELLIOT J MARTIN CHIROPRACTIC
Disclosed Feb 24, 201610 years ago1,200 affectedConfirmed
An unauthorized user established a user account with administrative privileges on the covered entity's (CE) computer system which contained the electronic protected health information (ePHI) of 1,200 patients. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ran malware detection software and reviewed software logs that showed activities from the CE's computer. The CE changed its Internet Protocol (IP) address, router, passwords and installed a physical firewall on its computer system. The CE also changed its policy so that it does not request or maintain patients’ Social Security numbers. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and implement certain improvements to its processes regarding information system activity review and information access management.
What is known
| People affected | 1,200 (as reported to HHS) |
|---|---|
| Disclosed | Feb 24, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): ELLIOT J MARTIN CHIROPRACTIC (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 24, 2016 | 1,200 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.