Skip to content

Memorial Sloan Kettering Cancer Center

Disclosed Sep 14, 20206 years ago73,536 affectedConfirmed

Official notice

The covered entity (CE), Memorial Sloan Kettering Cancer Center, reported that employees of its business associate misconfigured a server and exposed the protected health information (PHI) of 18,913 individuals. The PHI involved included names, Social Security numbers, dates of birth, addresses, financial information, diagnoses, lab results, medications prescribed, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided free credit monitoring and fraud protection services, sanctioned workforce members responsible for the breach, and took the affected network server offline.

What is known

People affected73,536 (as reported to HHS)
DisclosedSep 14, 2020
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 14, 202073,536
HHS archivetotalMar 31, 202118,913

Other breaches at Memorial Sloan Kettering Cancer Center

BreachAffected
Disclosed Jun 25, 2024Jun 25, 20242 years agoHacking12K
Disclosed Nov 13, 2013Nov 13, 201312 years agoLost or stolen device2,279
Disclosed Jun 8, 2012Jun 8, 201214 years agoLost or stolen device568
History of this record
  • 2026-09-25 · records: 18913 to 73536 · backfill source
  • 2026-09-25 · disclosed: 2021-03-31 to 2020-09-14 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Memorial Sloan Kettering Cancer Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.