The medical practice reported the incident to HHS on March 5 as affecting 28,658 people. In a statement posted on its website, Mendelson Kornblum said it discovered the breach Jan. 5 and that one of its computer servers “was and had been for an unknown period of time vulnerable to viewing by unauthorized third parties.”
The patient information exposed included names, medical record numbers, birth dates, sex, and certain data regarding medical images. The exposed information did not include any medical images, Social Security numbers of financial data, according to the breach notice.
Mendelson Kornblum said it launched an investigation into the incident and identified and closed the vulnerability on the computer server to prevent additional exposure.
More articles on cybersecurity:
Class action targets UPMC over data breach
CISA, FBI warn of new TrickBot malware campaign: 10 tips to protect your hospital
Ransomware attack exposes 27,000+ Arizona health plan members’ data for 2.5 weeks
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.