The records included insurance forms, social security number and physicians’ notes.
Owner Joel Hecht said the company posted the records on a website it believed only employees had access to, according to the report. However, Aaron Titus, a researcher with Identity Finder, found the company’s medical records through Internet searches.
Mr. Titus said the company did not require a password or prohibit search engines from indexing the pages, two steps that could have prevented the data breach. Mr. Hecht said the company’s internal security policies were not followed.
Related Articles on Data Breaches:
meridianEMR Files Lawsuit Against UroChart for Alleged Data Breach
Delaware’s St. Francis Hospital Recovers Thumb Drive With Nearly 500 Patients’ Information
Keeping Data Out of the Wrong Hands: 10 Tips for Hospital Data Security Training
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.