Skip to content

Middlesex Hospital

Disclosed Dec 4, 201510 years ago946 affectedConfirmed

Official notice

Four Middlesex Hospital employees responded to a phishing email, resulting in the disclosure of the protected health information (PHI) of 945 individuals. The information accessed included patients’ names, addresses, dates of birth and social security numbers. The covered entity (CE), provided breach notification to HHS, affected individuals, and the media. The CE also set up a dedicated call center to answer questions for affected individuals and provided affected individuals with 12 months of credit monitoring services at no cost. Following the breach, the CE developed a mandatory Phishing Awareness and Response Training program for employees and required additional training for all supervisors and managers to provide to their staff. Additional mitigation included the designation of March as “Cyber Awareness” month, which includes the implementation of a number of tools to educate staff on cyber threats, separate personal meetings and trainings between those employees whose accounts had been compromised, and the procurement of a vendor to conduct social engineering testing to assess the effectiveness of the CE's staff training. The CE also upgraded its anti-virus program and will

What is known

People affected946 (as reported to HHS)
DisclosedDec 4, 2015
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Middlesex Hospital (Healthcare Provider, CT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 4, 2015946
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Middlesex Hospital

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.