An investigation into the incident indicates the unauthorized access occurred from July 6 to July 7, 2016. The health system said it his no evidence the hackers accessed or acquired protected health information from the email account, but could not rule out the possibility.
Information accessible in the employee’s email account includes certain clients’ names, addresses, birth dates, Social Security numbers, physician names, diagnoses, disability codes, health insurance numbers, treatments, treatment locations and medical record numbers. The type of information at risk varies for individuals, according to the notification.
According to HHS’ Office for Civil Rights breach notification portal, the cyberattack affects 7,748 individuals.
Burrell Behavioral Health said it took counter measures following the attack and has established a dedicated assistance line for anyone seeking information about the incident.
“We take any threat to the security of information entrusted to us very seriously,” said Todd Schaible, PhD, president and CEO of Burrell Behavioral Health. “We apologize for any inconvenience or concern this incident may cause our community.”
More articles on data breaches:
The role all executives play in cybersecurity
RI gastroenterology center alerts patients to possible breach after finding encrypted files
Asante reports internal data breach
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.