Skip to content

Montefiore Medical Center

Disclosed Jul 22, 201511 years ago12,517 affectedConfirmed

Official notice

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with Montefiore Medical Center, a non-profit hospital system based in New York City for several potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. OCR is responsible for administering and enforcing health information privacy, including enforcement of the HIPAA Privacy, Security, and Breach Notification Rules for the health care sector. OCR plays a unique role in serving as the agency at HHS that enforces federal civil rights, privacy and security laws in health care. HIPAA requires that health care providers, insurers and others take steps to protect the privacy and security of patients’ protected health information. The $4.75 million monetary settlement and corrective action resolves multiple potential failures by Montefiore Medical Center relating to data security failures by Montefiore that led to an employee stealing and selling patients’ protected health information over a six-month period. “Unfortunately, we are living in a time where cyber-attacks from malicious insiders are not uncommon. Now more than ever,

What is known

People affected12,517 (as reported to HHS)
DisclosedJul 22, 2015
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJul 22, 201512,517

Other breaches at Montefiore Medical Center

BreachAffected
Disclosed Sep 14, 2020Sep 14, 20206 years agoLost or stolen device76K
Disclosed Mar 9, 2010Mar 9, 201016 years agoLost or stolen device24K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Montefiore Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.