Vendor ransomware attack exposes patient data at Tennessee hospital

Memphis, Tenn.-based Regional One Health’s obstetrics and gynecology patients’ information may have been compromised due to a ransomware attack on a technology vendor KMJ Health Solutions.

Advertisement

On Jan. 18, KMJ notified the University of Tennessee Health Science Center, which supplies residents to Regional One, that its hosting provider, Liquid Web, had found signs of a ransomware attack. KMJ provides patient handoff software to the university. The attack allowed hackers to gain access to information stored on one of KMJ’s servers.

The server contained protected health information of patients who received OB-GYN services at Regional One between November 2014 and November 2023.

The information compromised included first and last names, medical record numbers, ages, dates of admission, allergies, services, resident assigned, parity, diagnoses, prenatal provider, laboratory results, medications, fetal or delivery details, contraception, type of infant feeding and information regarding follow-up care.

No financial or bank account information was compromised, according to Regional One.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.