In a notification letter to affected individuals, the Texas Department of Aging and Disability Services indicated a web application intended for internal use only was accessible on the Internet.
The application contained patient information including names, residences, addresses, birth dates, Social Security numbers, Medicaid numbers, medical diagnoses and treatment information.
DADS learned of the data breach April 21, 2015 and immediately took down the website and launched an investigation, according to the notification letter.
Currently, the agency reports having no reason to believe any information has been misused.
Cecilia Cavuto, a spokeswoman for DADS, told the American-Statesman the patient data may have been unintentionally posted online when data handling responsibilities transferred departments. Ms. Cavuto said human error is the likely culprit of the breach.
“I don’t think we have the answer to what exactly caused this breach just yet,” Ms. Cavuto told the American-Statesman. “It looks like the application was developed without the appropriate security. It was supposed to be an internal application, which points to human error.”
According to the notification letter, DADS has strengthened its policies, procedures and web-application security.
More articles on data breaches:
Cybersecurity: Weighing the price of prevention vs. recovery
50 things to know about healthcare data security & privacy
5 top data breach trends for this year
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.