Five things to know:
1. Med-Data notified Memorial Hermann and UChicago Medicine of the breach March 31. The company said it discovered the incident in December, CBS affiliate KHOU reports.
2. An internal investigation found that a former Med-Data employee saved client files to personal folders created on a public-facing website sometime during or before September 2019. Med-Data removed the files Dec. 17, 2020.
3. UChicago Medical Center said almost 900 of its patients may have been affected by the security breach at Med-Data, according to the Chicago Sun-Times.
“The exposure of information occurred on Med-Data’s end,” the hospital said in a statement. “At this time, the company has confirmed it has no knowledge of any actual or attempted misuse of the information of our patients.”
4. The files uploaded to the website contained information including patients’ names and in some cases birthdates, Social Security numbers, addresses and healthcare data.
5. Med-Data did not say whether it would press charges against the former employee who uploaded the information. The company is offering affected individuals a free year of credit monitoring and identity theft protection services.
More articles on cybersecurity:
Does a vaccine passport violate HIPAA? Experts weigh in
More than 1 million affected by data breaches in March
Humana employee identities being used to file fraudulent unemployment claims
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.