NRAD Medical Associates
Disclosed Jun 20, 201412 years ago97,000 affectedConfirmed
NRAD Medical Associates, the covered entity (CE), reported that an employee impermissibly downloaded 96,998 patients’ protected health information (PHI) onto a desktop computer and a personal external hard drive. The PHI included patients’ names, addresses, dates of birth, dates of service, social security numbers, procedure and diagnosis codes. The CE provided breach notification to HHS, affected individuals, and the media. During OCR’s investigation, the CE sanctioned a physician and filed for Chapter 11 bankruptcy. The CE transferred all of its assets to another imaging group and hospital. Ultimately, the CE ceased its operations and thus was no longer covered by the HIPAA Rules.
What is known
| People affected | 97,000 (as reported to HHS) |
|---|---|
| Disclosed | Jun 20, 2014 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): NRAD Medical Associates (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 20, 2014 | 97,000 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.