On Feb. 22, one employee at the Casper-based medical center opened a phishing email and clicked on the included link. On Feb. 25, a second employee opened another phishing email.
Although the hospital remains unsure of who was responsible for phishing scheme, whoever it was had access to the employees’ email accounts for 15 minutes, according to Matt Frederiksen, WMC’s chief compliance officer.
The accessible records included patients’ names, medical record account numbers, dates of hospital service, birth dates and some medical information. Personal addresses, Social Security numbers and insurance information were not in the email records.
“They had access to limited patient information,” said Mr. Frederiksen. “They never had access to our electronic medical record system.”
Hospital spokeswoman Kristy Bleizeffer said there isn’t evidence that that patients’ health information was viewed, copied or acquired, according to the report.
WMC notified the affected patients April 20. It has also informed the U.S. Department of Health and Human Services Office for Civil Rights.
More articles on health IT:
How bitcoin’s sister technology could change the future of healthcare
US Coast Guard terminates Epic contract
Google, Apple, Microsoft employees have raised $435k for Bernie Sanders
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.