IU Health reports vendor security incident affecting radiology files

Advertisement

Indianapolis-based Indiana University Health identified unauthorized access to information associated with certain Southern Indiana patients’ radiology files following a vendor security incident.

IU Health learned Aug. 4 that its IT vendor, AME Group, may have been susceptible to a previously unknown software vulnerability affecting services it provided to an isolated IU Health legacy system, according to a Sept. 29 news release.

The health system verified the security of its own systems and conducted an independent review of the external system managed by AME. That review identified unauthorized access to limited imaging center information stored on the legacy system.

IU Health said there was no evidence its network or core systems were affected. Its electronic medical record system was not accessed, and patient care was not affected.

The information involved varied by individual but may have included names, dates of birth, health plan member identification numbers and limited treatment information associated with the imaging center.

IU Health began notifying affected individuals Sept. 29 and is providing dedicated call center support.

Advertisement

Next Up in Cybersecurity

Advertisement