Jackson (Ala.) Hospital is notifying 13,910 individuals that their data may have been breached in a cybersecurity incident involving a debt collector.
The hospital said it discovered in late January that its patients’ information was compromised in a July 2024 hack of Nationwide Recovery Services. The breached data may have included names, addresses, dates of birth, phone numbers, Social Security numbers, health insurance information and dates of service.
Other hospitals and health systems have been involved in the vendor’s breach, including UChicago Medicine Medical Group, Murphy, N.C.-based Erlanger Western Carolina Hospital and Greenwood, S.C.-based Self Regional Healthcare.
Jackson Hospital started the notification process and told HHS of the incident in late February.