Skip to content

Memorial Sloan Kettering Cancer Center

Disclosed Jun 8, 201214 years ago568 affectedConfirmed

Official notice

The covered entity's (CE) staff member disclosed an unencrypted Microsoft Excel graph to a non-covered entity physician who re-disclosed it to a medical education organization to be used in a presentation. In addition, the medical education organization posted the presentation slides on its website. The graph contained the protected health information (PHI) of 569 individuals and included names, telephone numbers, social security numbers, ages, cities and states of residence, medical record numbers, and clinical information. Upon discovery of the breach, the CE ensured that the information was removed from the website and deleted, sanctioned the workforce member responsible, and retrained its workforce on the use of a data loss prevention tool and the risks of embedded PHI. As a result of OCR's investigation, the CE provided OCR with evidence of its technical safeguards and security awareness initiatives and provided assurance that it implemented the corrective action listed above.

What is known

People affected568 (as reported to HHS)
DisclosedJun 8, 2012
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJun 8, 2012568

Other breaches at Memorial Sloan Kettering Cancer Center

BreachAffected
Disclosed Jun 25, 2024Jun 25, 20242 years agoHacking12K
Disclosed Sep 14, 2020Sep 14, 20206 years agoInsider74K
Disclosed Nov 13, 2013Nov 13, 201312 years agoLost or stolen device2,279
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Memorial Sloan Kettering Cancer Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.