Skip to content

Weill Cornell Medicine

Disclosed Feb 23, 20267 months ago516 affectedConfirmed

Official notice

The covered entity (CE), Weill Cornell Medicine, reported that an employee inappropriately accessed patients’ protected health information (PHI) without approval or authorization. According to the breach report, the breach affected approximately 516 individuals. The PHI involved demographic and treatment information. The CE notified HHS and the affected individuals. In its mitigation efforts, the CE sanctioned the employee and reviewed its access controls. OCR provided technical assistance to the CE regarding the HIPAA Rules.

What is known

People affected516 (as reported to HHS)
DisclosedFeb 23, 2026
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Weill Cornell Medicine (Healthcare Provider, NY)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalFeb 23516

Other breaches at Weill Cornell Medicine

BreachAffected
Disclosed Nov 12, 2021Nov 12, 20214 years agoHacking26K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Weill Cornell Medicine

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.