EHR vendor cyberattack exposes nearly 320,000 patients’ info 

QRS, a health IT and EHR software company, recently began notifying its provider clients of a cyberattack on a patient portal server that exposed almost 320,000 patients’ personal information. 

Advertisement

QRS reported the breach to HHS on Oct. 22 as affecting 319,778 individuals. The EHR vendor said a hacker accessed one of its dedicated patient portal servers between Aug. 23-26, according to its online data security incident notice. 

The hacker accessed, and may have acquired, files on the server containing patients’ information, the company said. This information included patients’ names, Social Security numbers, addresses, birthdates, patient ID numbers and diagnosis details. 

The attack did not involve any other QRS systems or systems belonging to any of the company’s healthcare clients, and QRS is providing free identity theft protection services for any individuals whose Social Security numbers were involved in the incident.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.