DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CT Attorney General investigating MidState Medical/Hartford Healthcare breach

Posted on April 7, 2011 by Dissent

In the aftermath of the breach involving MidState Medical Center, Connecticut’s Attorney General George Jepsen and Consumer Protection Commissioner William M. Rubenstein are asking Hartford Healthcare and its Midstate Medical Center affiliate in Meriden for more information about a data breach that may have compromised medical records of 93,500 patients.

The hospital notified the Attorney General that a hard drive containing protected health information and personal information was taken home by an employee of Hartford Healthcare and subsequently lost. The hard drive contained patient names, addresses, dates of birth, Social Security numbers and medical record numbers.

“I strongly believe in protecting the confidentiality of patients’ private information. Hospitals, like health insurance companies, have access to very sensitive health and personal information. They have a duty to protect that information from unlawful disclosure,” Attorney General Jepsen said.

In a letter to the hospitals’ attorney, Jepsen asked that affected patients be provided with two years of credit monitoring services, identity theft insurance, and reimbursement for the costs associated with placing and lifting security freezes. “When protected information is lost or otherwise disclosed, the hospitals have a responsibility to help protect the identities of the individuals affected,” Jepsen said.

Jepsen and Commissioner Rubenstein are seeking more information about the hospitals’ policies and practices to protect patient information, how the breach occurred and what is being done to keep it from happening again.

“Connecticut law requires companies and organizations that collect and hold personal data to have stringent controls in place to protect that data,” Rubenstein said. “Ensuring that companies comply with the law before consumers get hurt is always more effective than trying to protect consumers after a breach. We will assess the hospitals’ security protocols to assure that a system is in place to prevent this kind of breach from happening again.”

Assistant Attorney General Matthew Fitzsimmons is handling this matter for Jepsen.

Source: Attorney General Jepsen


Related:

  • Paying cyberattackers is wrong, right? Should Taos County's incident be an exception? (1)
  • HHS OCR Settles HIPAA Ransomware Investigation with Syracuse ASC for $250k plus corrective action plan
  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Theft from Glasgow’s Queen Elizabeth University Hospital sparks probe
Category: Health Data

Post navigation

← Who should be notifying consumers about the Epsilon breach?
ME: State Prisoner Sentenced For False Tax Claims and Misuse of Social Security Numbers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hackers post stolen St. Paul data online as efforts to reset city employee passwords surge forward
  • Justice Department Announces Coordinated Disruption Actions Against BlackSuit (Royal) Ransomware Operations
  • NL: Hackers breach cancer screening data of almost 500,000 women
  • Violent Crypto Crimes Surge in 2025 Amid Massive Data Leaks
  • Why Ransomware Attacks Are Decreasing in 2025
  • KR: Yes24, the largest Internet bookstore in Korea, suffered its second ransomware attack in two months
  • Korea wins world’s top hacking contest for 4th consecutive year
  • 7-Zip Vulnerability Lets Hackers Write Files and Run Malicious Code
  • Connex Credit Union notifies 172,000 members of hacking incident
  • Federal judiciary says it is boosting security after cyberattack; researcher finds new leaks (CORRECTED)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Navigating Privacy Gaps and New Legal Requirements for Companies Processing Genetic Data
  • Germany’s top court holds that police can only use spyware to investigate serious crimes
  • Flightradar24 receives reprimand for violating aircraft data privacy rights
  • Nebraska Attorney General Sues GM and OnStar Over Alleged Privacy Violations
  • Federal Court Allows Privacy Related Claims to Proceed in a Proposed Class Action Lawsuit Against Motorola
  • Italian Garante Adopts Statement on Health Data and AI
  • Trump administration is launching a new private health tracking system with Big Tech’s help

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.