Middletown Medical
Disclosed Mar 29, 20188 years ago63,551 affectedConfirmed
A misconfigured radiology interface application permitted unauthorized individuals to access 63,551 patients’ electronic protected health information (ePHI). The ePHI affected by this incident included patients’ names, dates of birth, client identification numbers, dates of service, and, for approximately 250 patients, radiology reports and images. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE secured the radiology application so that only authorized staff could access it, amended its policies and procedures to require that all systems and their security settings be tested in a test environment prior to live deployment, and trained relevant workforce members regarding this policy change. The CE also sanctioned the workforce member responsible for this incident. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to perform a risk analysis and establish a risk management plan, and document the unauthorized disclosure of its patients’ ePHI for accounting of disclosure purposes. Also, the CE is expected to perform a technical and non-technical ev
What is known
| People affected | 63,551 (as reported to HHS) |
|---|---|
| Disclosed | Mar 29, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Middletown Medical (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 29, 2018 | 63,551 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.