Skip to content

Memorial Sloan Kettering Cancer Center

Disclosed Nov 13, 201312 years ago2,279 affectedConfirmed

Official notice

Memorial Sloan Kettering Cancer Center, the covered entity (CE), reported that a former employee’s personal unencrypted external computer hard drive was lost or stolen. The drive contained the protected health information (PHI) of 2,279 of the CE’s patients and included names, addresses, telephone numbers, dates of birth, medical record numbers, physician names, appointment dates, procedure type, and clinical information. The CE notified HHS, the media, and the affected individuals. Following the breach, the CE obtained assurances from the employee and his current employer that the PHI was deleted from all devices, computers and servers. The CE purchased and implemented an encryption solution to encrypt all data copied from its workstations, USB and external drives. The CE retrained employees on its HIPAA policies and procedures and reinforced its policies prohibiting the use of personal portable electronic data storage devices. During the investigation, OCR obtained assurances that the CE implemented the corrective actions. The CE is expected to conduct a risk analysis and implement a corresponding risk management plan.

What is known

People affected2,279 (as reported to HHS)
DisclosedNov 13, 2013
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalNov 13, 20132,279

Other breaches at Memorial Sloan Kettering Cancer Center

BreachAffected
Disclosed Jun 25, 2024Jun 25, 20242 years agoHacking12K
Disclosed Sep 14, 2020Sep 14, 20206 years agoInsider74K
Disclosed Jun 8, 2012Jun 8, 201214 years agoLost or stolen device568
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Memorial Sloan Kettering Cancer Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.