The imaging group learned of the incident in December and launched an investigation, which found that its medical records vendor’s IT infrastructure had security vulnerabilities that allowed unauthorized individuals to access the patient information between July 2019 and December 2020.
Patient information accessed included names, dates of births, study dates and types of imaging procedures performed, according to a Feb. 15 news release.
Sutter Buttes said it closed certain firewall ports to prevent future unauthorized access and began working with third-party IT consultants to increase its security controls.
More articles on cybersecurity:
Wyoming health system accidentally emails personal health info of 900 patients
HIPAA Right of Access cases surpass $1M –16 providers that have paid settlements
30 popular mobile health apps vulnerable to cyberattacks, PHI exposur
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.