Skip to content

Mount Sinai Hospital

Disclosed Aug 2, 20197 years ago33,730 affectedConfirmed

Official notice

The covered entity (CE), Mount Sinai Hospital, reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency (AMCA), was the victim of a cyber-attack involving the electronic protected health information (ePHI) of 33,730 individuals. The ePHI involved included names, dates of service, clinical information, and health insurance information. The CE notified HHS, affected individuals, and the media. OCR’s investigation resulted in the CE implementing additional administrative safeguards to better protect its sensitive data. As a consequence of this breach incident, the CE terminated its relationship with the BA.

What is known

People affected33,730 (as reported to HHS)
DisclosedAug 2, 2019
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mount Sinai Hospital (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 2, 201933,730

Other breaches at Mount Sinai Hospital

BreachAffected
Disclosed Jul 8, 2011Jul 8, 201115 years agoLost or stolen device712
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mount Sinai Hospital

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.