DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Two laptops with PHI stolen from UHS-Pruitt employees' cars in a two-week period

Posted on December 17, 2013 by Dissent

One of the breaches added to HHS’s public breach list today gave me a bit of a headache. Well, to be honest, they generally all give me a headache, but this one took me time to sort out. And although I may have a headache now, I suspect UHS-Pruitt may have a bigger headache. 

It seems that UHS-Pruitt Corporation in Georgia reported that 1,300 patients had PHI on a laptop that was stolen on September 26, 2013.

I could find no media coverage of the breach or notice on their site, but I was able to locate a cached copy of Georgia Public Notice that showed the following notice ran on November 15 in the Albany Herald, Dougherty County:

UHS-PRUITT CORPORATION NOTIFIES RESIDENTS OF BREACH OF UNSECURED PERSONAL INFORMATION

UHS-Pruitt Corporation (“UHS-Pruitt”) has provided notice to current and former residents of Heritage Healthcare of Ashburn, UniHealth Post-Acute Care Augusta Hills, Heritage Healthcare of Fitzgerald, Heritage Healthcare at Osceola, Palmyra Nursing Home and Sylvester Healthcare of a breach of unsecured resident medical and financial information after discovering the following event:

On September 26, 2013, a computer laptop belonging to an employee of UHS-Pruitt was stolen from the employee`s locked car. The theft was immediately reported to the police, and UHS-Pruitt continues to cooperate fully with the investigation. The computer laptop was used by the employee to access and maintain certain patient information for purposes of processing payment for health care services provided by the above-referenced nursing facilities.

Upon discovery of the theft, all access through the employee`s stolen laptop to computer applications on our shared system, such as electronic medical records, was cut off within a matter of hours. Nevertheless, UHS-Pruitt determined that documents containing lists of patient names and other identifying information, such as social security numbers, Medicare numbers, dates of birth, and resident ID numbers were also stored locally on the computer`s hard drive.UHS-Pruitt has not received any indication that such information stored on the computer has been accessed or used by an unauthorized individual at this time.

UHS-Pruitt is notifying impacted residents to mitigate any potential damages of the breach. UHS-Pruitt Corporation has safeguards in place to protect the privacy and security of resident health information. As a result of this breach, steps are underway to further improve the security of its operations including enhancing privacy and security policies and procedures, security training and improved technical protection of the data. In the notice to residents, UHS-Pruitt has informed the individuals of the steps they should take to protect themselves from potential harm resulting from the breach including placing a fraud alert on their credit report with the three major credit bureaus and examining their credit report for evidence of potential fraud. UHS-Pruitt`s Privacy Officer is available for residents to call with questions related to the data breach. Affected individuals may call (678)533-6437 or 1-800-222-0321 from 9:00 a.m. until 5:00 p.m., or call 1-800-222-0321 at any time to request a returned call from the Privacy Officer.

But wait (as the commercials say), there’s more….

In the process of researching this breach, I discovered a press release from UHS-Pruitt that seemed to contradict the media notice above. Then I realized the press release was from a UHS-Pruitt affiliate, UniHealth SOURCE, and it was reporting a second breach that also involved a laptop theft.

The December 6th  press release (pdf) reads, in part:

UniHealth SOURCE, a provider of case management services in the Georgia Service Options Using Resources in a Community Environment (SOURCE) Medicaid waiver program, is committed to our clients’ privacy and compliance with all applicable federal and state regulations. The purpose of this notice is to identify a recent incident involving the theft of a computer laptop belonging to one of our employees. The laptop contained very limited information about current and former clients: specifically, the first and last name and, in some cases, potential diagnoses. The laptop did not contain any other identifying information, such as Social Security numbers or dates of birth, which could be used by an identity thief to financially exploit our clients. Although the laptop did contain the names of approximately 4,500 current and former clients of UniHealth SOURCE, UniHealth Select, and Blue Ridge Community Based Services, the level of financial risk to these individuals appears to be very low.

On October 8, 2013, the employee’s laptop was stolen from her car at her home. The theft was reported to the police, and we continue to cooperate fully with the investigation. The computer laptop was used by the employee to access and maintain certain patient information for the purpose of quality assurance audits for health care services provided by the above-referenced offices. Upon discovery of the theft, all access through the employee’s stolen laptop to computer applications, such as electronic medical records, was cut off immediately. Nevertheless, we determined that the above-described patient information was stored locally on the computer’s hard drive. We have not received any indication that such information stored on the computer has been accessed.

I’ve sent an inquiry to UHS-Pruitt asking whether the employee(s) were violating any policies by having unencrypted PHI on their laptops and by leaving their laptops in their cars. I also inquired whether any employees were disciplined over these breaches, and will update this post if I get a response.

Related posts:

  • July theft of computer with Fairview patient data wasn't the first, Minnesota AG says
Category: Health Data

Post navigation

← Colorado Health & Wellness notifies patients after doctor who left practice took their contact information with him
Facebook rolls out a Donate Now button to help charities; will store your credit card info →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.