SSM Health learned of the incident Oct. 30 and immediately launched an internal investigation, which remains ongoing. Hospital spokesperson Brian Westrich declined comment to Becker’s Hospital Review for that reason.
While the employee had access to protected health information to perform his job duties, the individual was not granted access to financial information, such as credit or debit card numbers. The focus of his illegal activities involved the medical records of a small number of patients with a controlled substance prescription and a primary care physician in the St. Louis area.
The hospital said it has implemented corrective actions, including requiring an additional identifier when patients request prescription refills from the call center, reviewing internal policies and procedures, and strengthening employee access monitoring tools. SSM Health will also offer free identity theft protection to affected individuals.
More articles on cybersecurity:
Jones Memorial Hospital experiences computer downtime following cyberattack
What to know about 7 major types of cryptocurrencies
84k patient records exposed in November: 6 things to know
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.