The IT vendor told Boston Children’s about unusual activity on its systems Sept. 6, and the physician network noticed unauthorized activities on its network Sept. 10. The organization immediately shut down its systems as a proactive measure and worked with a third-party forensics firm to investigate the incident.
The investigation uncovered evidence the cybercriminal removed files from Boston Children’s Health Physicians’ network. The files included information with patient and employee information, Social Security numbers, birth dates, health insurance and billing information, and treatment information.
The physician network’s EHR systems were not affected by the incident. The organization, which includes 55 practices across New York and Connecticut, did not disclose how many patients were affected.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.