DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Curry Health Network notifies members of FastHealth breach

Posted on April 2, 2018 by Dissent

Last month, this site noted a FastHealth breach from 2017 that was first being disclosed.  FastHealth had reported it to HHS as impacting 1,345 patients. Now Curry Health Network is notifying its members, and it’s not totally clear if these members were included in the number that had been previously reported to HHS.  DataBreaches.net emailed FastHealth to see if they would clarify the numbers for this breach, but has received no response as yet. This post will be updated if a response is received. In the meantime, here is Curry Health Network’s notification:

(March 26, 2018) – Some community member may have received, or may be receiving, a letter from FastHealth Interactive Healthcare notifying them of a security incident. Curry Health Network has received inquiries from staff and community members regarding the legitimacy of the letter, and would like to share the following information:

FastHealth is a company with whom Curry Health Network (CHN) contracts to provide the hosting and programming for its web site. They provide these services to many hundreds of hospitals and other healthcare organizations. FastHealth stores the files which comprise the content and data submitted in forms on the CHN web site, on their servers in Alabama.

FastHealth determined, through a lengthy investigation, that an unauthorized third-party accessed their web server, and may have been able to acquire information from certain databases.

The database in question contained information submitted on the CHN employment application form, from which, again, information may or may not have been accessed. The information did not include Health Information protected by HIPAA, medical records, patient portal data, online bill pay information, or any other forms on the web site or linked to/from the web site.

FastHealth is required to notify persons who may have been affected by this unauthorized access to their server, and is in the process of sending letters to those whose information had the potential to be accessed.

FastHealth is offering one year’s identity monitoring services to all persons who receive the letter. This service includes credit monitoring, fraud consultation, and identity theft restoration.

To be clear – this incident is a FastHealth security issue; it is not a Curry Health Network security issue and does not reflect on the security of the CHN data systems. Additionally, the security of the web site does not fall under the purview of the Curry Health Network IT department, but rather to the vendor.

If you have received a letter, or receive a letter in the future, and have questions, comments or concerns, please contact the call center number included in the letter (1-833-215-3730).

Category: Breach IncidentsHackHealth DataSubcontractor

Post navigation

← TX: Personal info still being discarded and dumped improperly
Equifax has been sending some consumers hit by its data breach wrong letters →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Trump Rewrites Cybersecurity Policy in Executive Order
  • AMI Group – Travel & Tours notice of ransomware attack
  • Resource: Insider Threat reports
  • Za: Cyber extortionist sentenced to eight years in jail
  • ICE takes steps to deport the Australian hacker known as “DR32”
  • Hearing on the Federal Government and AI
  • Nigerian National Sentenced To More Than Five Years For Hacking, Fraud, And Identity Theft Scheme
  • Data breach of patient info ends in firing of Miami hospital employee
  • Texas DOT investigates breach of crash report records, sends notification letters
  • PowerSchool hacker pleads guilty, released on personal recognizance bond

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy Victory! Judge Grants Preliminary Injunction in OPM/DOGE Lawsuit
  • The Decision That Murdered Privacy
  • Hearing on the Federal Government and AI
  • California county accused of using drones to spy on residents
  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.