Patient information that was exposed includes names, addresses, dates of birth, medical record numbers and Medi-Cal identification numbers, according to the report. Additionally, the Social Security numbers of two patients were also revealed. L.A. County officials said it does not appear that any patient data was misused.
Nemadji Research helps L.A. County DHS identify and verify patients eligible for programs that can cover their care costs. The cyberattack occurred March 28 when a Nemadji Research employee opened an email, which permitted the hacker to access the company’s data for hours, LA Times reports.
L.A. County DHS operates four hospitals and 19 health centers, according to the department’s website.
Nemadji Research is providing free credit monitoring and identity protection services for any patients who may have been affected by the incident. The company also said it implemented enhanced employee email security training, according to a statement on its website.
More articles on cybersecurity:
Hospital CFOs are stepping into cybersecurity roles
US warns against Microsoft Outlook vulnerability
Smaller health systems struggle to follow cybersecurity best practices
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.