On Jan. 18, the associate noticed suspicious activity in one of their employee’s email accounts.
The business associate learned that the email account had been targeted by a phishing attack and was able to be accessed by an unauthorized user through a web browser.
The emails potentially affected contained patient information from the health system, such as names, patient account and/or medical record numbers, admission and/or discharge dates, status of diagnosis or discharge, and associated billing amounts.
Financial information such as Social Security numbers were not in the emails, according to the health system.
South Texas Health System said it does not believe protected health information within the emails were misused, however, it sent out notification letters to all affected on May 17.
The health system did not mention how many patients were affected by the breach.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.