Anderson, S.C.-based AnMed says files copied during its cybersecurity incident may have included patients’ Social Security numbers, driver’s license numbers and financial account information.
The health system said its investigation into the incident, first disclosed July 26, is nearly complete and has identified unauthorized copying of files from certain network systems.
AnMed said patient electronic medical records, stored primarily in a secure cloud environment, were not affected. However, the health system said some patient care files stored locally on its network may have included names alongside demographic details such as address, date of birth, Social Security number and driver’s license or other government-issued identification.
Clinical information, including diagnoses, treatment details, lab results and medications, and financial information, including health insurance claims data and payment card numbers, may also be involved.
AnMed said it is working with federal and state law enforcement and third-party specialists, and it has reported the incident to HHS. The health system said it has no indication that any individual has experienced confirmed identity theft as a result of the incident. AnMed said it will send direct notices to affected patients once its review of the compromised files is complete.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.