DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NY: Jamaica Hospital Medical Center employees charged with illegally accessing patient information that they provided to lawyers and "medical mills"

Posted on March 29, 2014 by Dissent

Queens District Attorney Richard A. Brown announced that two employees of Jamaica Hospital Medical Center in Queens, New York have been charged with illegally accessing medical records and personal identification information of emergency room patients who were then contacted — some while they were still in the emergency room  – by attorneys seeking to solicit them as clients and by others seeking to provide outpatient services.

District Attorney Brown identified the defendants as Maritza Amador, 44, of 8825 148th Street, in Jamaica, Queens, and Dache Prawl, 45, of 194-01 Linden Boulevard, in St. Albans, Queens. The defendants were arrested Friday night.  They are variously charged with computer trespass, second-degree unlawful possession of personal identification information, and unauthorized use of a computer. If convicted, they each face up to four years in prison.

It is alleged that both Amador and Prawl each illegally accessed more than 250 different computer records of patient files, each containing, among other things, the patient’s Social Security number, date of birth, address, telephone number, and details regarding their injuries and medical treatment received in the emergency room at Jamaica Hospital Medical Center.  The press release from District Attorney Brown’s office does not indicate which types of information were allegedly shared with the attorneys and “medical mills,” nor does it name the attorneys who solicited the patients or those who falsely claimed to be from the hospital to provide outpatient services.

According to the charges, defendant Amador, between February 10, 2012 and March 12, 2014, and defendant Prawl, between December 11, 2013 and March 17, 2014,  illegally accessed the personal identification information. Both defendants were employed as registrars in the emergency room of Jamaica Hospital Medical Center, but none of the patients were registered by either of them, and therefore they had no legitimate reason to access the information.

A sampling of the accessed files charged in the criminal complaints includes an individual who sought treatment in the emergency room for injuries suffered as a result of a car accident. The hospital’s computer logs showed that  less than two hours after the patient was registered,  defendant Amador used her computer access login to access the individual’s records of medical treatment.  Within two days of the emergency room visit, the patient received a phone call from a person falsely claiming that she was calling from Jamaica Hospital and she wanted to make sure that the patient received followup medical treatment. The patient also received a call from an attorney attempting to solicit the patient as a client relevant to the injuries which caused the emergency room visit.

In another case included in the complaint, defendant Prawl allegedly used her access to get the treatment records of another patient who had sought treatment for injuries suffered as the result of a motor vehicle accident. According to the hospital’s records, while the patient was still in the emergency room, the patient received calls from attorneys attempting to solicit the patient as a client. Additionally, less than one week later, the patient received a phone call from someone falsely representing that they were outside the patient’s home to transport the patient to outpatient therapy.

The hospital detected the breaches and notified law enforcement.

As of today’s date, the incident is not up on HHS’s public-facing breach tool, although it probably should appear at some point if 500 patients had their records improperly accessed and disclosed.

 h/t, WSJ

Category: Uncategorized

Post navigation

← Hacked Japanese Building Research Institute responds to hack
Public health, privacy rights collide in Pa. drug-tracking bill →

4 thoughts on “NY: Jamaica Hospital Medical Center employees charged with illegally accessing patient information that they provided to lawyers and "medical mills"”

  1. Anonymous says:
    March 30, 2014 at 1:31 am

    Damn, shame, lock them up and throw away the key.its always something at that hospital anyway. Im not surprised. Smh!!!!

  2. Anonymous says:
    April 6, 2014 at 6:02 pm

    It’s not the hospital ! It’s those kind of employees with no brains bringing the institution down !!!

    1. Anonymous says:
      April 6, 2014 at 6:05 pm

      And who hires those employees? Who does the background checks? Who implements logs and auditing to prevent and catch bad actors? The hospital, so suggesting they’ve got no responsibility just will not pass muster.

      1. Anonymous says:
        April 8, 2014 at 10:07 am

        Although healthcare facilities cannot control the bad actions of all of their employees, I agree wholeheartedly with Dissent that they are responsible for exercising due diligence in their hiring practices. A small critical access hospital where I previously worked had excellent background check policies that have, on occasion, discovered something that did not prevent someone from becoming employed but did result in a “we’re aware of this issue” discussion with the employee and closer monitoring of the employee. Healthcare facilities are also responsible for educating and monitoring their workforce.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.