DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UNCG Discovers Health Information Security Breaches; 2,500 Being Notified

Posted on August 10, 2010 by Dissent

From the University of North Carolina – Greensboro (UNGG) statement:

Computer security breaches at two UNCG clinics allowed unauthorized access to information about more than 2,500 individuals.

The university has mailed letters to the last known addresses of those whose personal information was exposed and posted notices on the clinics’ websites. The two computers infected with malware via the Internet were in the university’s Speech and Hearing Center and Psychology Clinic.

Although the problems were discovered days apart in June, they are believed to be unrelated. Employees of the clinics and Information Technology Services have been working since then to determine what records were vulnerable and who might be affected. It is not known how long the breaches lasted before detection. Although it was determined that the malware would have allowed access to data on the computers, it is unknown whether any information was actually taken from the computers.

[…]

The bulk of the impacted records are in the Speech and Hearing Center, where a breach was found June 10 and corrected the same day. The compromised computer was used for billing and contained records for about 2,300 people who have received services from the Center since 1997. Vulnerable data included names, addresses, social security numbers, dates of birth, telephone numbers, insurance companies, insurance ID numbers, group numbers, diagnosis codes, procedure codes and charges.

The problem at the Psychology Clinic, involving malware on a computer used to document incoming phone calls, was detected and fixed June 7. The vulnerable computer contained a spreadsheet with names, dates of birth, telephone numbers, cities of residence, whether or not callers had insurance and dates of contact from about 240 callers between Sept. 20, 2006, and Sept. 22, 2009. In some cases, the spreadsheet also contained reference to the caller or caller’s family member as “client,” symptoms reported by the caller, reference to an inquiry about testing or evaluation, and reference to “therapist/treatment/provider and/or services.” No social security numbers appeared on the spreadsheet.

The Psychology Clinic computer also held 18 phone intake/client data forms from March 2009 through June 2010. The forms included names, ages, dates of birth, telephone numbers, addresses, insurance providers (if any), social security numbers and dates of contact. In some cases, one or more of the following types of information also appeared on the form: therapist, case number, status of previous treatment, service requested and description of the problem.

Source: UNGG

Related – UNGG Speech and Hearing Center, UNGG Psychology Clinic


Related:

  • Two years after an audit highlighted significant concerns, North Salem Central School District leaves sensitive student data at risk
  • University of Pennsylvania says it wasn't hacked after a vulgar email was sent to campus community
  • Veradigm's Breach Claims Under Scrutiny After Dark Web Leak
  • Massive Great Firewall Leak Exposes 500GB of Censorship Data
  • UK: Woman charged after NHS patients' records accessed in data breach
  • Landmark civil penalty of AU$5.8 million issued under Australia’s Privacy Act
Category: Breach IncidentsEducation SectorHealth Data

Post navigation

← What To Do When Your Database Gets Breached
Laptops stolen from Jewish Hospital contained patient data on 2,089 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.