Select Health discovered unusual activity in an employee’s email account. Upon further investigation, the physician group determined that the employee’s email account was accessed by an unauthorized third party between May 22 and June 13.
Patient data that may have been exposed included names, addresses, dates of birth, member identification numbers, treating/referring physicians, health insurance information, medical history information, treatment information, treatment cost information, health insurance policy numbers and medical record numbers. A limited number of Social Security numbers may have also been affected.
Select Health said there is no evidence that patient information has been misused.
“As part of our ongoing commitment to the privacy of personal information in our care, we are working to review our existing policies and procedures and to implement additional safeguards to further secure the information in our systems,” Select Health said in a statement.
More articles on cybersecurity:
DNA-testing company informs consumers of data breach
Maine provider alerts 30,000 patients of data breach
How hospitals should approach cybersecurity
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.