Mercy Health discovered that a private server was vulnerable to unauthorized personnel between 2014 and March 25, 2019. The server was used to store patient information and allowed physicians to conduct office check-ins and schedule appointments.
Patient information that may have been exposed included names, addresses, emails, insurance information and dates of birth. A limited number of Social Security numbers and some patient diagnosis information were also potentially accessible.
There is no evidence that information has been misused, Mercy Health reports.
More articles about health IT:
HHS OIG warns against genetic testing scam
Battle of the coasts: How Boston-based digital health companies compete with Silicon Valley for tech talent
Smaller tech ‘tweaks’ add up to make a big impact on clinical care
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.