Stamford Podiatry Group .P.C
Disclosed May 25, 201610 years ago40,491 affectedConfirmed
On April 14, 2016, the covered entity (CE), Stamford Podiatry Group P.C., learned that an unauthorized individual(s) had gained privileged access and compromised its computer server between February 2, 2016 and April 14, 2016, including its electronic record database. The breach affected 40,491 individuals and included demographic, financial, and clinical information. OCR reviewed the CE's policies and procedures as relevant to this breach and they appeared to be in compliance with the Privacy and Security Rule. The CE retrained staff, implemented an upgraded, more secure data backup solution, and enhanced safeguards for its information technology (IT) system, including completely rebuilding its IT operating environment. The CE implemented new risk management policies and plans, improved its processes for managing and monitoring its vendors, and reduced the amount of PHI and personally identifiable information in its possession. OCR obtained assurances that the CE provided breach notification to affected individuals and the media in accordance with the Breach Notification Rule.
What is known
| People affected | 40,491 (as reported to HHS) |
|---|---|
| Disclosed | May 25, 2016 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Stamford Podiatry Group .P.C (Healthcare Provider, CT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | May 25, 2016 | 40,491 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.