DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Wayne Memorial Hospital notified patients after CD with their unencrypted records was lost in the mail

Posted on February 7, 2013 by Dissent

This was reported by James Haggerty on January 23, but I just stumbled across it now:

A compact disc including information on Medicare patients at Wayne Memorial Hospital disappeared recently en route to its intended recipient.

An administrator at Wayne Memorial in Honesdale on Nov. 28 sent the unencrypted disc and related paperwork by certified mail to the Pittsburgh office of Novitas Solutions Inc., a Camp Hill-based Medicare administrative contractor, the hospital reported.

Although it was mailed in a legal envelope, Wayne Memorial officials say it arrived at Novitas’s Pittsburgh offices in a cardboard box without the disc. They were notified Dec. 3 that the disc was missing.

Hospital officials suspect the original package was damaged at a postal facility, the disc was lost and the paperwork was inserted into another package, which was delivered to Novitas.

The disc contained the names of 1,182 people who had been Medicare patients at the Honesdale hospital between 2007 and 2012 and have account balances outstanding, hospital spokeswoman Lisa Champeau said. Most of the patients’ Medicare account numbers were included on the disc, she said.

Read more on Citizens Voice.

On January 22, the hospital posted the following notice, linked from their home page:

Privacy Notification for Wayne Memorial Patients

On December 3, 2012, Wayne Memorial Hospital (WMH) discovered that this CD containing patient information had gone missing. An investigation was launched immediately. The hospital assured patients every step was being taken to address the incident and to protect their privacy.

The CD was included in a package sent by certified mail to WMH’s government authorized Medicare Administrative Contractor. The contractor received the package damaged and without the CD. Upon learning this, WMH conducted a diligent search for the CD with both the United States Post Office and the contractor. To date, WMH has been unable to locate the CD. The investigation confirmed that the CD contained names of patients who used WMH services between 2007 and 2012, account balances and, in some instances, Medicare numbers.

WMH administrators said they have no reason to believe that any of the information has been accessed or used improperly. However, in an abundance of caution, the Hospital has established a dedicated call center for those affected. WMH is also offering to eligible individuals one year of credit monitoring services provided through Experian. More information can be found at the WMH website at www.wmh.org.

WMH deeply regrets any inconveniences or concerns that this incident may cause those affected. The Hospital takes this incident very seriously and is reviewing its policies and procedures to ensure patient information is protected. The Hospital is committed to protecting all patient information and educating staff hospital-wide on the importance of maintaining the confidentiality of patient information entrusted to Wayne Memorial.

The News Eagle reports that notification letters were sent out beginning January 18.

Category: Health Data

Post navigation

← EU proposes new cybercrime reporting rules
Montgomery woman sentenced to prison for stealing personal info of 800 Troy Regional Medical Center patients →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.