DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Three new breaches revealed by HHS/OCR

Posted on November 14, 2010 by Dissent

While I was away, I see that there was another update to HHS’s breach tool web page:

Debra C. Duffy, a dentist in Texas, reported that 4,700 patients were notified of a breach that occurred on August 5 that involved the theft a laptop. I do not see a notice on her web site, so if anyone has additional info, please use the Comments section to add information. [Updated May 22, 2011: Dr. Duffy posted an updated breach notice on her web site in January 2011 that lists all of the data types involved in the breach, including treatment information, graphic images, and Social Security numbers.]

Northridge Hospital Medical Center in California reported that 837 patients were affected by a breach that occurred on October 16 involving the loss of paper records. A notice on their home page says, “Northridge Hospital Medical Center has experienced a security incident involving Medicare and Medi-Cal patient information. If you were a patient at our Hospital between September 2004 and June 2006, please visit our Security Alert Page for details.” That notice says, in part:

On October 18, 2010, Northridge Hospital Medical Center discovered that a package sent thru a national courier containing information for 716 Medicare and Medi-Cal patients was damaged in transit, potentially exposing patient information to courier employees. We have no reason to believe that the information left the confines of the courier’s facilities.

Northridge Hospital has sent letters offering credit monitoring services to all Medicare and Medi-Cal patients whose personal/sensitive information may have been exposed. If you were a patient between September 2004 and June 2006 and have not received a letter or have questions, please contact 1-877-906-1590.

The documents may have contained patient names, addresses, phone numbers, social security numbers, guarantor social security number, date of birth, date of death, medical record number, admission and discharge dates, discharge summary, physician, procedure, notes for pregnancy-related emergency, admission, financial account number, provider number, insurance ID, Medicare or Medi-Cal charges billed and paid, hospital room and board charges, Medi-Cal ID number, California Children’s Services Authorization, and Medi-Cal Treatment Authorization.

It’s not clear why the number reported in the notice is discrepant from the one reported to HHS.

Aetna Insurance of Connecticut reported that 2, 345 insured were affected by a breach that occurred in September involving Unauthorized Access/Disclosure. So far, I haven’t found any additional details on this incident, but will keep searching. If you have a copy of the notification, please send it in.

No related posts.

Category: Health Data

Post navigation

← Patient and personal info exposed when package sent by courier damaged in transit
Five Floridians charged with stealing patient info from HCH and doctor's office →

1 thought on “Three new breaches revealed by HHS/OCR”

  1. Anonymous says:
    November 15, 2010 at 10:37 pm

    Aetna is usually pretty good about protecting privacy. I assume they corrected things quickly.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hunters International to provide free decryptors for all victims as they shut down (1)
  • SEC and SolarWinds Seek Settlement in Securities Fraud Case
  • Cyberattacks Disrupt Iran’s Bread Distribution, Payments Remain Frozen
  • Hacker with ‘political agenda’ stole data from Columbia, university says
  • Keymous+ Hacker Group Claims Responsibility for Over 700 Global DDoS Attacks
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • DOJ investigates ex-ransomware negotiator over extortion kickbacks
  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute
  • Wisconsin Supreme Court’s Liberal Majority Strikes Down 176-Year-Old Abortion Ban

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.