The affected patients received care at the former Centennial, Colo.-based Centura Health, which now operates under the CommonSpirit name, and were exposed via the use of Nuance Communications, a Microsoft subsidiary that listens to and documents medical appointments, according to a Sept. 13 notice from CommonSpirit. Nuance employed the MOVEit file transfer software from Progress Software that was hacked in late May.
The breached data may include patient and facility names, dates and types of service performed, and medical record numbers. The health system is mailing letters to affected patients.
The worldwide hack has affected a variety of industries and at least 60 million people. Other health systems that had patient information exposed in the breach include Baltimore-based Johns Hopkins Medicine, Dallas-based UT Southwestern Medical Center, and Louisville, Ky.-based UofLHealth. Clop, a ransomware gang with ties to Russia, has claimed responsibility for the data theft.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.