The attack occurred between April 20 and April 27, during which an unauthorized third party used phishing tactics to obtain several employees’ email login credentials and gain access to their email accounts. An investigation revealed one or more of the affected accounts contained PHI and other personal information of patients or employees.
Although NYOH doesn’t have evidence that its patients’ or employees’ information has been misused, the center has notified and provided 12 months of credit reporting services to its more than 128,400 patients and employees, according to The Record. Patients and employees who joined NYOH after April 27 were not affected.
“We deeply regret any inconvenience or concern this incident may cause our patients and employees,” reads a notice on the organization’s website. “We are taking precautionary steps to ensure patient safety, privacy and peace of mind. To help prevent something like this from happening again, NYOH will continue to look for ways to enhance our systems, training and controls against these threats.”
More articles on cybersecurity:
Future of cybersecurity threats & the recipe for a perfect cyber storm: Hospital for Special Surgery CISO shares insights
Health First Florida phishing attack may have compromised 42,000 patients
600 providers weigh in on their information security backup systems
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.