DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Carolinas HealthCare System notifies Carolinas Medical Center-Randolph patients after e-mail intrusion

Posted on December 7, 2012 by Dissent

From a statement posted today:

Carolinas HealthCare System is notifying approximately 5,600 patients of Carolinas Medical Center-Randolph (CMC-Randolph) whose private information may have been breached by an unauthorized electronic intruder and approximately 700 additional patients of the affected provider as a precautionary measure even though no evidence has been found that their information was obtained by the intruder. The intruder obtained incoming and outgoing emails from a provider’s account without the provider’s or the hospital’s knowledge.

The security breach was discovered on October 8, 2012 following an upgrade in the hospital’s security software. Based on the investigation, the intruder obtained emails from the provider’s account between March 11, 2012 and October 8, 2012. Upon discovery of the breach, immediate steps were taken to prevent further access by the intruder to the affected email account. Carolinas HealthCare System hired a forensic investigator and notified federal law enforcement of the incident.

Based on information discovered through the investigation, most of the obtained emails did not contain patient information. While only five emails contained social security numbers, a number did contain some medical and other patient information. The emails appear to include one or more of the following: patient names, dates and times of service, provider and facility names, internal hospital medical record and account numbers, dates of birth, and treatment information, such as diagnosis, prognosis, medications, results and referrals. Potentially affected patients have been sent personal letters explaining the type of information involved.

At this time, Carolinas HealthCare System has no evidence that the information has been misused, and based on the investigation, no other email accounts or other computer systems (including the electronic medical records system) were found to have been affected by this incident.

Read more on their web site.

h/t, WSOCTV.com

Related posts:

  • Insider Threat: Fake Therapist Fooled Hundreds Online Until She Died, State Records Say
Category: Health Data

Post navigation

← State Farm and Nationwide fail to convince WV Supreme Court to let them retain – and share – medical records obtained under protective orders
100+ Sites hacked and defaced by Anonymous Pakistan →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware
  • Senator Chides FBI for Weak Advice on Mobile Security
  • Cl0p cybercrime gang’s data exfiltration tool found vulnerable to RCE attacks
  • Kelly Benefits updates its 2024 data breach report: impacts 550,000 customers
  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Kids are making deepfakes of each other, and laws aren’t keeping up
  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.