DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

More additions to HHS's breach tool

Posted on May 21, 2013 by Dissent

Two updates within a week? The HHS breach tool is getting a workout.  Here is what was added today:

Sovereign Medical Group, LLC in New Jersey reported that 27,800 were affected by a breach on October 10, 2012. HHS’s breach tool codes the incident as “Theft, Hacking/IT Incident”, Network Server,” which probably means a hack, but I’ve found no media coverage of this breach and have sent them an inquiry.

South Jersey Hospital Inc. disclosed in January that they were affected by the Omnicell breach reported previously on this blog. Why their report to HHS is first appearing on HHS’s breach tool is unclear to me: were they late in notifying HHS, or did HHS delay posting this while they investigated? HHS has informed me in the past that they do not add incidents to the breach tool until they’ve done a preliminary verification of certain details. Looking at the other entries in this latest batch, my guess is that HHS delayed posting these incidents while they investigated.

Hawaii State Department of Health, Adult Mental Health Division disclosed a breach in October 2012 that is also first appearing on HHS’s breach tool. According to the entry, 674 clients were affected by a hack that occurred on September 25, 2012.

L.A. Care Health Plan in California reported that 18,000, were affected by an unspecified breach that occurred between September 17 and September 20, 2012. That breach had previously been reported on this blog and involved a mailing error that sent members’ IDs to the wrong addresses.

Calvin Schuster, MD of California reported that 532 patients had data on a computer stolen November 14, 2012. That breach was previously reported on this blog. Somewhat confusingly – or perhaps it’s a typo on HHS’s tool or in the doctor’s letter to patients – the log entry shows the theft occurred on November 14, while Dr. Schuster’s letter to patients says they learned of the breach on November 5.

SilverScript Insurance Company in Arizona, a CVS Caremark company and Medicare Part D Plan insurer, reported a breach affecting 852 patients on October 31, 2012. That breach involved paper records,  and might be a mailing error, but I can find no documentation of this breach available online.

Raleigh Orthopaedic Clinic in North Carolina’s breach affecting 17,300 patients was also added to the breach tool. That incident, involving stolen x-rays, was previously reported on this blog.


Related:

  • Ransomware blog claims New Horizons Medical has been attacked
  • Little Rock Psychologist Indicted by Federal Grand Jury for Defrauding Medicare and Arkansas Blue Cross Blue Shield
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • Large medical lab in South Africa suffers multiple data breaches
  • From bad to worse: Doctor Alliance hacked again by same threat actor (2)
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
Category: Health Data

Post navigation

← NYPD detective charged with hacking
Idaho State University Settles HIPAA Security Case for $400,000 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How old is the average hacker? What does a new research report suggest? (1)
  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
  • Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies
  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Update on Dos-OP’s report on Nova RaaS
  • KR: Privacy Commissioner’s Office Urges the Public to Beware of Fraudsters Exploiting the Tai Po Fire Disaster
  • Cyber attack on Indian airports? Govt explains the scary threat that disrupted 400 flights last month.
  • How a noisy ransomware intrusion exposed a long-term espionage foothold
  • KR: Hacking scheme targeted 120,000 home cameras for sexual footage

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.