Middlesex Hospital
Disclosed Dec 4, 201510 years ago946 affectedConfirmed
Four Middlesex Hospital employees responded to a phishing email, resulting in the disclosure of the protected health information (PHI) of 945 individuals. The information accessed included patients’ names, addresses, dates of birth and social security numbers. The covered entity (CE), provided breach notification to HHS, affected individuals, and the media. The CE also set up a dedicated call center to answer questions for affected individuals and provided affected individuals with 12 months of credit monitoring services at no cost. Following the breach, the CE developed a mandatory Phishing Awareness and Response Training program for employees and required additional training for all supervisors and managers to provide to their staff. Additional mitigation included the designation of March as “Cyber Awareness” month, which includes the implementation of a number of tools to educate staff on cyber threats, separate personal meetings and trainings between those employees whose accounts had been compromised, and the procurement of a vendor to conduct social engineering testing to assess the effectiveness of the CE's staff training. The CE also upgraded its anti-virus program and will
What is known
| People affected | 946 (as reported to HHS) |
|---|---|
| Disclosed | Dec 4, 2015 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Middlesex Hospital (Healthcare Provider, CT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 4, 2015 | 946 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.