vz-risk / VCDB

VERIS Community Database
Other
568 stars 180 forks source link

Email Accounts Compromised at BJC HealthCare & Cooper University Health Care #18702

Open swidup opened 2 years ago

swidup commented 2 years ago

https://www.hipaajournal.com/email-accounts-compromised-at-bjc-healthcare-cooper-university-health-care/

swidup commented 2 years ago

BJC HealthCare, a non-profit healthcare organization based in St. Louis, MO, has started notifying certain patients that some of their protected health information was stored in email accounts that were accessed by an unauthorized individual.

The investigation confirmed that a small number of email accounts of physicians and general practitioners had been accessed between March 4 and March 28, 2022. The forensic investigation did not determine whether emails and attachments had been viewed or copied, but unauthorized data access and theft could not be ruled out.

A comprehensive review of the email accounts confirmed they contained names, dates of birth, medical record numbers, and clinical information such as performance dates, diagnoses, provider names, and/or treatment locations. A limited number of patients also had their health insurance information, driver’s license numbers, and/or Social Security numbers exposed.

Individuals who had either their driver’s license number or Social Security number exposed can take advantage of the complimentary credit monitoring and identity theft protection services that have been offered.

The incident has yet to appear on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.