Skip to content

Hospital for Special Surgery

Disclosed Mar 17, 201610 years ago647 affectedConfirmed

Official notice

The Hospital for Special Surgery, the covered entity (”CE”) reported that an employee failed to safeguard the PHI by sending the email without using the BCC designation; in doing so, the email revealed the PHI of 647 patients participating in a research study to the other participants. The electronic protected health information (ePHI) included the individuals’ email addresses and general information regarding the research study. The CE provided notice to OCR and the affected individuals. Following the breach, the responsible employee was re-trained and provided with one-on-one, in-person HIPAA Privacy and Information Security Training. The CE also increased its in-person HIPAA training to at least three times a year. As a result of OCR’s investigation and technical assistance, the CE is expected to take corrective action based on OCR’s guidance. The CE is expected to revise its e-mail policy to incorporate additional safeguarding measures specifically tailored to the use of e-mail, and to retrain its staff on its revised policy.

What is known

People affected647 (as reported to HHS)
DisclosedMar 17, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalMar 17, 2016647

Other breaches at Hospital for Special Surgery

BreachAffected
Disclosed Jan 21, 2014Jan 21, 201412 years agoLost or stolen device937
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Hospital for Special Surgery

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.