Penn Medicine’s Chief Privacy Officer Lauren Steinfeld said the medical assistant was a contract employee who worked at the hospital between February and late April. It is unclear which department the employee had worked for.
The hospital became aware that the employee was viewing patient records “without a work-related reason,” on April 29, Ms. Steinfeld said. Information that may have been exposed included demographic and clinical information. A limited number of Social Security numbers may have also been viewed.
In one case, a patient’s information was “misused,” Ms. Steinfeld confirmed. However, it is unclear how the information had been used.
Penn Medicine is evaluating its staffing agencies and contractors “to ensure that contract employees meet and maintain our high professional standards,” Ms. Steinfeld said.
More articles on cybersecurity:
Oregon State Hospital alerts patients of phishing attack
Memorial Hermann employee ‘improperly’ used patients’ credit card info
First cybercrime hotline unveiled in Rhode Island
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.