DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NY: 18,000 North Shore University Hospital- LIJ patients notified 8 months after data theft at business associate’s offices

Posted on June 19, 2015 by Dissent

Candic Ruud reports:

The North Shore-Long Island Jewish Health System is warning about 18,000 patients that their personal, health and insurance information is at risk due to a potential data breach.

Five laptops were stolen last September from the offices of Global Care Delivery, a Texas-based firm that contracted with North Shore-LIJ and other providers to process and collect payments owed by insurers to hospitals, officials said Friday.

Four of the laptops may have files containing information on about 18,000 North Shore-LIJ patients — including names, dates of birth, internal account numbers, diagnosis and procedure codes, and insurance identification numbers, according to the health system.

Read more on Newsday.

If the business associate discovered this breach on September 2, notification of the covered entity in May is way past the 60 days specified in HITECH. I wonder if HHS will fine them for this serious delay.

Update: Here’s the notification letter template to NSUH patients. The notification indicates that the types of PHI involved included:

  • name
  • date of birth
  • insurance identification number
  • Social Security number
  • limited clinical information

Their notification to the NH Attorney General’s Office indicates that the “limited clinical information” refers to diagnostic and treatment codes.

Neither letter explains the 8-month delay between the theft of the password-protected (but not encrypted) laptops and their notification to NSUH-LIJ.


Related:

  • UN Cybercrime Convention to be signed in Hanoi to tackle global offences
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Toys “R” Us Canada customers notified of breach of personal information
  • Gatineau gymnastics centre warns members of possible data breach
  • Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats
Category: Breach IncidentsBusiness SectorHealth DataOf NoteSubcontractorTheftU.S.

Post navigation

← Lithuanian Military Website hacked to post false information
Ca: House of Commons says data theft warning a ‘miscommunication’ →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.