DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

More additions to HHS's breach tool

Posted on May 21, 2013 by Dissent

Two updates within a week? The HHS breach tool is getting a workout.  Here is what was added today:

Sovereign Medical Group, LLC in New Jersey reported that 27,800 were affected by a breach on October 10, 2012. HHS’s breach tool codes the incident as “Theft, Hacking/IT Incident”, Network Server,” which probably means a hack, but I’ve found no media coverage of this breach and have sent them an inquiry.

South Jersey Hospital Inc. disclosed in January that they were affected by the Omnicell breach reported previously on this blog. Why their report to HHS is first appearing on HHS’s breach tool is unclear to me: were they late in notifying HHS, or did HHS delay posting this while they investigated? HHS has informed me in the past that they do not add incidents to the breach tool until they’ve done a preliminary verification of certain details. Looking at the other entries in this latest batch, my guess is that HHS delayed posting these incidents while they investigated.

Hawaii State Department of Health, Adult Mental Health Division disclosed a breach in October 2012 that is also first appearing on HHS’s breach tool. According to the entry, 674 clients were affected by a hack that occurred on September 25, 2012.

L.A. Care Health Plan in California reported that 18,000, were affected by an unspecified breach that occurred between September 17 and September 20, 2012. That breach had previously been reported on this blog and involved a mailing error that sent members’ IDs to the wrong addresses.

Calvin Schuster, MD of California reported that 532 patients had data on a computer stolen November 14, 2012. That breach was previously reported on this blog. Somewhat confusingly – or perhaps it’s a typo on HHS’s tool or in the doctor’s letter to patients – the log entry shows the theft occurred on November 14, while Dr. Schuster’s letter to patients says they learned of the breach on November 5.

SilverScript Insurance Company in Arizona, a CVS Caremark company and Medicare Part D Plan insurer, reported a breach affecting 852 patients on October 31, 2012. That breach involved paper records,  and might be a mailing error, but I can find no documentation of this breach available online.

Raleigh Orthopaedic Clinic in North Carolina’s breach affecting 17,300 patients was also added to the breach tool. That incident, involving stolen x-rays, was previously reported on this blog.


Related:

  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Theft from Glasgow’s Queen Elizabeth University Hospital sparks probe
  • North Country Healthcare responds to Stormous's claims of a breach
  • Texas Enacts Electronic Health Record Data Localization Law
Category: Health Data

Post navigation

← NYPD detective charged with hacking
Idaho State University Settles HIPAA Security Case for $400,000 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders
  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.