DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Curry Health Network notifies members of FastHealth breach

Posted on April 2, 2018 by Dissent

Last month, this site noted a FastHealth breach from 2017 that was first being disclosed.  FastHealth had reported it to HHS as impacting 1,345 patients. Now Curry Health Network is notifying its members, and it’s not totally clear if these members were included in the number that had been previously reported to HHS.  DataBreaches.net emailed FastHealth to see if they would clarify the numbers for this breach, but has received no response as yet. This post will be updated if a response is received. In the meantime, here is Curry Health Network’s notification:

(March 26, 2018) – Some community member may have received, or may be receiving, a letter from FastHealth Interactive Healthcare notifying them of a security incident. Curry Health Network has received inquiries from staff and community members regarding the legitimacy of the letter, and would like to share the following information:

FastHealth is a company with whom Curry Health Network (CHN) contracts to provide the hosting and programming for its web site. They provide these services to many hundreds of hospitals and other healthcare organizations. FastHealth stores the files which comprise the content and data submitted in forms on the CHN web site, on their servers in Alabama.

FastHealth determined, through a lengthy investigation, that an unauthorized third-party accessed their web server, and may have been able to acquire information from certain databases.

The database in question contained information submitted on the CHN employment application form, from which, again, information may or may not have been accessed. The information did not include Health Information protected by HIPAA, medical records, patient portal data, online bill pay information, or any other forms on the web site or linked to/from the web site.

FastHealth is required to notify persons who may have been affected by this unauthorized access to their server, and is in the process of sending letters to those whose information had the potential to be accessed.

FastHealth is offering one year’s identity monitoring services to all persons who receive the letter. This service includes credit monitoring, fraud consultation, and identity theft restoration.

To be clear – this incident is a FastHealth security issue; it is not a Curry Health Network security issue and does not reflect on the security of the CHN data systems. Additionally, the security of the web site does not fall under the purview of the Curry Health Network IT department, but rather to the vendor.

If you have received a letter, or receive a letter in the future, and have questions, comments or concerns, please contact the call center number included in the letter (1-833-215-3730).

Category: Breach IncidentsHackHealth DataSubcontractor

Post navigation

← TX: Personal info still being discarded and dumped improperly
Equifax has been sending some consumers hit by its data breach wrong letters →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.