DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Rotech Healthcare notifies patients whose details were found in possession of unauthorized individual

Posted on August 17, 2016 by Dissent

Rotech Healthcare Inc., a provider of home respiratory and medical equipment equipment and supplies, notified HHS of a breach involving 957 patients. Here is their notification:

Rotech Healthcare Inc. (“Rotech”) would like to notify you of a recent incident that may affect the security of your personal and protected health information. We are providing you with information regarding the incident, steps we have taken since discovering the incident and what you can do to protect against the possibility of identity theft and fraud should you feel it is appropriate to do so.

What Happened?

On June 13, 2016, Rotech received a report that certain patient information had been recovered by law enforcement after being found in the possession of an unauthorized individual. After receiving this report, Rotech immediately launched an investigation to verify the information provided and to learn more about whatmayhavehappened. Third-party forensic investigators were retained to assist with the investigationinto what happened, the identification of what information may be at risk and to whom this information relates. On July 11, 2016, the United States Secret Service provided Rotech with copies of the patient information recovered. A review of the recovered records indicates the records came from Rotech systems.

What Information Was Involved?

Although the investigations into this incident by Rotech and law enforcement are ongoing, Rotech determined that the paper records recovered by law enforcement contained your personal and protected health information, including : name, Social Security number, patient number, address, the name of the Rotech subsidiary company from which you received health care services, and possibly phone number and/or date of birth.

What We Are Doing?

Rotech takes your privacy and the security of your personal and protected health information very seriously, and we are cooperating with law enforcement’s investigation into this incident. Rotech and our third party forensic investigators continue to investigate this incident to identify any additional patients who may be impacted by this incident.

We are providing notice to all patients whose information was provided to Rotech by law enforcement and will notify any additional impacted individuals as they are identified. As part of our ongoing commitment to the security of the information in our care, we are reviewing our existing policies and procedures to better prevent something similar from happening again. We are notifying the Department of Health and Human Services and certain state regulators about this incident.

What You Can Do.

You can review the enclosed Steps You Can Take to Protect Against Identity Theft and Fraud. There you will find guidance on how to better protect against the possibility of identity theft and fraud. We know you may have questions about the content of this letter and have established a confidential, toll-free hotline to assist you with these questions and the steps you can take to better protect against the possibility of identity theft and fraud. The hotline is available Monday through Saturday, 9:00 a.m. to 9:00 p.m., EST, at 1-855-269-6650.

We sincerely regret any inconvenience this incident may cause. Rotech remains committed to safeguarding information in our care and will continue to take proactive steps to enhance the security of the information in our care.

Sincerely,

R. Wayne Bradberry, CHC
Vice President, Compliance & Ethics


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
Category: Health DataPaperU.S.

Post navigation

← Athens Orthopedic Clinic patient data still exposed on leak site
NV: Fraudulent Unemployment Claims Targeted State Employees →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • US, allies sanction Russian bulletproof hosting services for ransomware support
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • Large medical lab in South Africa suffers multiple data breaches
  • Report released on PowerSchool cyber attack
  • Sue The Hackers – Google Sues Over Phishing as a Service
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • Eurofiber admits crooks swiped data from French unit after cyberattack
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data
  • India’s Digital Personal Data Protection Act 2023 brought into force
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.