DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Comanche County Memorial Hospital notifies 2,199 patients after contractor’s email gaffe

Posted on May 19, 2016 by Dissent

On April 25, Comanche County Hospital Authority notified HHS that 2,199 patients were affected by an email incident. From their press release:

Comanche County Memorial Hospital issues public notice of HIPAA Breach

Lawton, OK (April 27, 2016) – Comanche County Memorial Hospital (CCMH) is committed to protecting the privacy of its patients and maintaining the highest standards in patient confidentiality. Although there is a very low risk to patients, CCMH was recently notified that an incident occurred with patients of the Memorial Medical Group (MMG), affiliated with CCMH. This incident resulted in a limited amount of patient information being released.

On February 26, 2016, the company contracted to provide patient satisfaction surveys for the MMG determined that an e-mail survey sent to numerous patients included incorrect information. The surveys were sent to the e-mail addresses of patients who visited MMG physicians from December 1 through December 31, 2015. The subject line of the e-mail stated the name of an individual that did not match the name of the individual to whom the e-mail was addressed. Within the body of the survey, the individual who received the e-mail was asked about their experience with a physician they had visited in recent weeks, but indicated that the physician worked in a different practice from the practice where the physician actually works. The surveys did not include any diagnoses or dates the physician was seen. They also did not contain any insurance or financial information of either the individual to whom the survey was sent or the individual whose name was in the subject line of the e-mail. They also did not include any identifying information about the individual other than the individual’s name. No social security numbers, addresses or phone numbers were disclosed.

Upon the outside company’s discovery of the erroneous surveys, the Privacy Officer at CCMH was notified and a thorough internal investigation was conducted whereupon it was determined that the error as reported by the outside vendor was correctly identified. As a result of this error, the outside vendor is updating and revising its procedures to ensure this error does not occur again. The employees of the vendor who were responsible for the error received disciplinary action up to and including termination from employment. CCMH and the MMG are closely monitoring the ongoing performance of this vendor to determine whether its services will be continued. Services will only be continued if they can be certain that the cause of the error has been satisfactorily corrected by the vendor.

All persons who were personally affected by this incident will receive a letter as long as their current mailing address is on file with the MMG physician’s office where they received care. The letter they receive will inform them that their name may have been attached to a survey sent to another individual who received care with a physician with the MMG.

CCMH regrets any inconvenience or concern that this error may cause, and encourages anyone who has questions to contact our dedicated toll free hotline at 1.855.731.6012.

For more information go to www.ccmhonline.com.

About Comanche County Memorial Hospital

Comanche County Memorial Hospital (CCMH) is a 283-bed not-for-profit county hospital in Lawton, Oklahoma and the regional referral center in Southwest Oklahoma.

The Memorial Medical Group (MMG) is the largest physician practice in Southwest Oklahoma and operated by CCMH. MMG is comprised of over 100 providers from 20 medical specialties.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Gatineau gymnastics centre warns members of possible data breach
  • Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • KT Chief to Resign After Cybersecurity Breach Resolution
Category: Breach IncidentsExposureHealth DataSubcontractor

Post navigation

← Another Bizmatics, Inc. client notifies 7.500 patients of hack
Utah man accused of hacking United Airlines →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.