DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MO: Choice Rehabilitation notifies patients after hack of corporate email account

Posted on December 31, 2018 by Dissent

The following notice from Choice Rehabilitation is dated December 18, 2018, but first appeared in STLToday on December 31, 2018:

December 18, 2018

Choice Rehabilitation of Creve Coeur, MO notified more than 500 residents of a breach of unsecured resident health information after discovering the following event:

On November 7, 2018, Choice Rehabilitation, (Choice) discovered that a corporate email account had been hacked. The hacker gained unauthorized access and was able to forward emails to a personal account which was later deactivated. It is not known whether the hacker has viewed the emails. In a detailed review of emails, Choice identified billing documents that were sent to associated skilled nursing facilities which included personal information relating to patients and the therapy services they received.

After consulting with Microsoft, Choice believes that this suspicious activity from July 1, 2018 through September 30, 2018.

Currently, there is no indication that there has been any use of the disclosed health information. Nevertheless, Choice has provided a notice to each patient out of an abundance of caution because their information was available through an attachment within an email and potential access to or acquisition of that information, before the account was locked down, could not be definitively ruled out.

There was no highly sensitive information such as personal contact information, Social Security numbers, dates of birth, Medicare/Medicaid numbers or any financial data included in the hacked emails . The emails did include billing information for physical, occupational and speech therapy. Personal information related to this billing included the patient’s full name, patient’s facility medical record #, payor such as Medicare, start and end of therapy care dates, medical and treatment diagnosis, therapy billing codes including minutes and the facility name. Choice believes there is a low probability of reputational or financial harm to the patient with this limited information. In conjunction with the contracted skilled nursing facilities and security experts, Choice and the associated facilities are working to notify impacted residents to mitigate the potential damages of the breach.

Upon discovering this incident, Choice took immediate action to secure the impacted email account and further alerted other corporate email account users of security safeguards that will be monitored and additional safeguards that have been implemented. In a notification to residents and/or their responsible party, Choice has offered their resources as well as informed the individuals of steps they should take to protect themselves from potential harm resulting from the breach.

Finally, Choice has taken security measures to strengthen its’ network against similar incidents in the future.

Choice Rehabilitation understands the importance of safeguarding residents’ personal information and takes that responsibility very seriously. We regret that this incident has occurred, and we are committed to safeguarding resident information from future unauthorized access. Steps are underway to further improve the security of its operations and we will continue to provide reminders and training for employees to avoid being victimized by hackers and phishing emails in the future to the extent possible.

Contact Choice Rehabilitation’s Compliance Officer toll free at 855900-0855 from 8 AM and 5 PM or email greeves@ choicerehab.net with questions related to the breach.

(Originally published in the St. Louis Post-Dispatch for 12/31/2018)

Category: HackHealth DataU.S.

Post navigation

← UK: Man finds confidential police reports in the road
Happy New Year 2019 →

1 thought on “MO: Choice Rehabilitation notifies patients after hack of corporate email account”

  1. HAS says:
    January 2, 2019 at 2:41 pm

    Noteworthy: 2 Entities using insecure communications to transfer ePHI.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.