Arizona Medical Practice Completely Loses EHR System in Ransomware Attack
Discover how an Arizona medical practice lost 35,000 patient records when ransomware encrypted both primary and backup EHR files, and how to prevent...
2 min read
Megan Schutz : Published Updated
Recently, personal data was leaked from over 100,000 patients at HealthReach Community Health Centers in Maine. How did this happen? Simple: by improper disposal of the health center’s hard drives (source).
Let’s dive into this deeper.
The hard drives from the healthcare giant were disposed of by an employee at a third-party data storage location. The breach took place in early April but was not uncovered until a month later when the investigation found that PII (personally identifiable information) and PHI (protected health information) of patients were compromised. Compromised information included names, birth dates, addresses, medical insurance information, social security numbers, medical records, lab results, and treatment records. Despite the leak of sensitive data, the provider noted that no data was misused due to the breach.
As is common practice in the fallout of this type of breach, patients impacted can enroll in complimentary identity theft protection services for one year of monitoring, identify theft recovery services and a one million dollar reimbursement policy. Affected patients were encouraged to do so.
PK Tech has worked in the healthcare space for over ten years. We can help with risk assessments, ongoing services, and more. Reach out to us for a consultation.
Discover how an Arizona medical practice lost 35,000 patient records when ransomware encrypted both primary and backup EHR files, and how to prevent...
Current and former employees pose a security risk to organizations, a reality that c-suite execs must confront if they prioritize safety.
To avoid a major data leak, University Hospital New Jersey paid $670,000 to stop a ransomware attack that threatened 240 GB of patient data.