Six things to know:
1. VPCHC discovered suspicious activity on an employee email account Nov. 27.
2. It immediately launched an investigation, which determined an unauthorized third party had access to the email account dating back to Oct. 26.
3. Health center officials were unable to determine which individual emails stored in the account may have been opened. Potentially compromised information includes:
- Names
- Addresses
- Social Security numbers
- Dates of birth
- Diagnosis, procedure or treatment information
- Provider information
- Patient identification numbers
- Medical record numbers
- Information regarding payment
4. For a limited amount of patients, bank account information, routing numbers, health insurance group numbers and member numbers may have also been compromised.
5. VPCHC’s investigation is ongoing, but officials do not have any evidence that the hacker has misused patient information held in the email account. As a precaution, the health center is offering affected individuals free credit monitoring services.
6. As of Feb. 1, information regarding the data breach has not yet been posted to the HHS’ Office for Civil Rights breach portal, which requires HIPAA-covered entities to report data breaches affecting 500 or more individuals.
More articles on cybersecurity:
Medical images especially vulnerable to alterations during cyberattacks, researchers say
Florida OB-GYN practice hit with ransomware, affecting files dating back to 2007
8 healthcare privacy incidents in January
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.