Frank R. Laurri, M.D. and Associates, P.C. Data Breach
NY Medical Practice Unauthorized EMR Access Affects 2,673 Patients
What happened in the Frank R. Laurri, M.D. and Associates, P.C. data breach?
The Frank R. Laurri, M.D. and Associates, P.C. data breach was reported on February 7, 2023 and affected 2,673 individuals. The breach type was Unauthorized Access/Disclosure involving Electronic Medical Record. This breach occurred in New York. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Frank R. Laurri, M.D. and Associates, P.C. Breach Details
Frank R. Laurri, M.D. and Associates Data Breach Report
Incident Overview
On February 7, 2023, Frank R. Laurri, M.D. and Associates, P.C., a medical practice based in New York, reported a data breach involving unauthorized access to patient electronic medical records (EMRs). The breach resulted in the exposure of protected health information (PHI) for approximately 2,673 individuals. The unauthorized access incident was discovered during routine security monitoring and investigation procedures, prompting immediate notification to affected patients and regulatory authorities as required under HIPAA Breach Notification Rule requirements.
Discovery and Response Timeline
The medical practice identified the unauthorized access through internal security controls and monitoring systems. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify which patient records were accessed without authorization, and assess what specific data elements may have been compromised. The practice notified affected individuals of the breach in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. The submission date of February 7, 2023, indicates the breach was reported to the New York Department of Health and Human Services as required for breaches affecting residents of New York State.
Breach Mechanism and Technical Details
The breach involved unauthorized access to the practice's electronic medical record system, which typically stores comprehensive patient health information including diagnoses, treatment plans, medications, and clinical notes. Unauthorized access incidents in medical settings can occur through various vectors including compromised user credentials, inadequate access controls, insider threats, or exploitation of system vulnerabilities. The fact that this breach was classified as an "unauthorized access/disclosure" rather than a theft or loss suggests that the breach likely involved either an individual with legitimate system access who exceeded their authorization scope, or an external actor who gained access through system vulnerabilities or credential compromise. No business associate was involved in this breach, indicating the unauthorized access occurred directly within the practice's own systems rather than through a third-party vendor or service provider.
Organizational Context
Frank R. Laurri, M.D. and Associates, P.C. is a medical practice operating in New York State. As a physician-led practice, the organization likely provides direct patient care services and maintains comprehensive electronic health records as part of standard clinical operations. The practice's size, as evidenced by the patient population affected, suggests a multi-provider practice with significant patient volume. Medical practices of this scale typically employ electronic health record systems to manage patient information, schedule appointments, process billing, and coordinate care. The practice's location in New York places it under the jurisdiction of New York State's health information privacy laws in addition to federal HIPAA requirements.
Patient Impact and Affected Population
Approximately 2,673 patients of Frank R. Laurri, M.D. and Associates were affected by this unauthorized access incident. These individuals had their electronic medical records accessed without authorization, meaning their sensitive health information was potentially exposed to unauthorized parties. The affected patients likely included individuals who had received care at the practice over an extended period, as EMR systems typically contain historical patient information accumulated over years of treatment relationships. Notification letters were sent to all affected individuals informing them of the breach, the types of information that may have been accessed, and recommended steps to protect themselves from potential misuse of their health information. The notification process is a critical component of HIPAA compliance and provides patients with the information necessary to monitor for identity theft, medical fraud, or other harmful consequences of the breach.
Data Exposure and Privacy Implications
Electronic medical records typically contain highly sensitive personal health information including patient names, dates of birth, medical record numbers, insurance information, diagnoses, treatment histories, medication lists, laboratory results, and clinical notes. In some cases, EMR systems may also contain Social Security numbers, financial information, or emergency contact details. The unauthorized access to these records creates significant privacy risks for affected patients, as this information could potentially be used for identity theft, medical fraud, insurance fraud, or sold to third parties for illicit purposes. The sensitivity of health information makes this breach particularly concerning, as medical data is often considered more valuable than financial data on the dark web due to its utility for fraudulent purposes and the difficulty patients face in detecting medical identity theft.
HIPAA Compliance and Regulatory Context
Under the HIPAA Breach Notification Rule, covered entities like medical practices must notify affected individuals, the media (if more than 500 residents are affected), and the Secretary of Health and Human Services of breaches of unsecured PHI. The fact that this breach involved 2,673 individuals indicates that media notification may have been required depending on the geographic concentration of affected patients. HIPAA requires that breach notifications include the date of the breach, the date of discovery, a description of the types of information involved, steps individuals should take to protect themselves, what the covered entity is doing to investigate the breach and prevent future incidents, and contact information for questions. Unauthorized access breaches represent a significant category of healthcare data breaches, accounting for a substantial portion of reported incidents in the healthcare industry. These breaches often result from inadequate access controls, insufficient employee training, or exploitation of system vulnerabilities, highlighting the importance of strong information security practices in healthcare settings.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Frank R. Laurri, M.D. and Associates, P.C. Breach
Monitor credit reports and consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized accounts from being opened in your name
Review medical bills and explanation of benefits statements carefully for any services you did not receive or charges you do not recognize, and contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Consider enrolling in identity theft protection and credit monitoring services, which may be offered by the medical practice at no cost; monitor your credit for unauthorized accounts or inquiries
Contact Frank R. Laurri, M.D. and Associates directly to confirm what specific information was accessed in your case and request additional details about the breach and recommended protective measures
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you believe your information has been misused, and consider filing a police report if you discover fraudulent activity
Request a copy of your medical records from the practice to verify accuracy and identify any unauthorized changes or additions to your health information
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New York Breaches
Search all breaches reported in New York