Rush exposes names of 908 patients in breach

Chicago-based Rush University Medical Center inadvertently exposed the names of 908 patients in a paper mailing announcing the retirement of a certified nurse practitioner at its Epilepsy Center.

Advertisement

Names listed on the outside of envelopes did not match the corresponding address, leading patients to receive the mailing with another patient’s name on it. The letter inside the envelopes was addressed “Dear Patient.” As no contact information was exposed, Rush deemed the breach low risk to patient privacy. Rush reported the data breach Feb. 11 to HHS’ Office for Civil Rights and has attempted to notify all patients involved.

“RUMC takes very seriously the privacy and security of our patients’ personal information and we regret that this incident happened. We have taken corrective action steps to ensure our privacy and security safeguards,” Andy Reeder, Rush HIPAA privacy and security officer, told patients in a letter about the breach. Rush partnered with ID Experts, a Portland, Ore.-based data breach services firm, to help manage its response.

 

More articles on cybersecurity:

NIH should strengthen information-security controls, OIG finds
Minnesota hospital alerts 2,000 patients of phishing scheme
AdventHealth notifies 42,000 patients of data breach

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

What clinicians need from AI after the pilot: Lessons from Adventist Health and Rady Children’s

Friday, July 24
12:00 PM - 1:00 PM CDT

Presenters: Dr. Dieter Sumerauer, Rady Children’s HealthDr. Salman Naqvi, AdventistDr. Reid Conant, Abridge

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.