Mount Sinai Beth Israel
Disclosed Oct 3, 201411 years ago10,793 affectedConfirmed
Mount Sinai Beth Israel, the covered entity (the CE), reported the theft of an unencrypted laptop computer containing the protected health information (PHI) of 10,793 patients from the Department of Obstetrics/Gynecology on-call room. The PHI consisted of demographic and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE reported the theft to law enforcement, remotely changed the password on the stolen laptop, enhanced physical safeguards and retrained staff on privacy and security issues related to data security and encryption. During the investigation, OCR obtained assurances that the CE implemented the corrective actions. As a result of the investigation, the CE is expected to implement a corresponding risk management and remediation plan as identified in its risk analysis. The CE is expected to implement a comprehensive policy and procedure for personally owned devices that have access to the CE’s electronic PHI to ensure that they are encrypted, tracked and monitored for encryption.
What is known
| People affected | 10,793 (as reported to HHS) |
|---|---|
| Disclosed | Oct 3, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mount Sinai Beth Israel (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Oct 3, 2014 | 10,793 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.