DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Penobscot Community Health Center notifying 13,000 patients about collection agency breach

Posted on July 13, 2019 by Dissent

Add Penobscot Community Health Center in Maine to the list of entities that had patients affected by the American Medical Collections Agency hack.They posted the following notice on their website:

PCHC values the privacy and confidentiality of its patients’ information. Regrettably, this notice is regarding the American Medical Collection Agency (AMCA) incident, which you may have recently heard about in the news or about which you recently received notice by letter. PCHC contracted with AMCA for billing collection services.

On May 15, 2019, AMCA advised PCHC that between August 1,2018 and March 30, 2019, an unauthorized person may have had access to AMCA’s systems. Some of PCHC’s patients’ information was contained in the AMCA system, including names, dates of birth, name of referring medical provider, and other medical information related to services received at PCHC. In some cases, patients’ credit card information may also have been contained in AMCA’s systems. AMCA has informed PCHC that no health records, diagnosis, or treatment information was impacted by this incident.

PCHC began mailing notification letters to affected patients on July 12, 2019. PCHC recommends affected patients review the statements they receive from their health care providers. If they see services they did not receive, please contact the provider immediately. If you believe you may have been affected by this incident and do not receive a letter by August 5, 2019, please call 1-844-243-3018, Monday through Friday, 9:00 a.m. to 6:30 p.m. Eastern Time.

PCHC deeply regrets any concern or inconvenience this incident may cause our patients. PCHC has since ceased doing business with AMCA and is taking steps to retrieve and secure all PCHC information contained in AMCA’s systems.

 

FAQs

Q1. What happened?

On May 15, 2019, American Medical Collection Agency advised us that between August 1,2018 and March 30, 2019, an unauthorized person may have had access to AMCA’s systems. PCHC contracted with AMCA for billing collection services. Some of our patients’ information was contained in the AMCA system, including names, dates of birth, name of referring medical provider, and other medical information related to services received at PCHC. In some cases, patients’ credit card information may also have been contained in AMCA’s systems. AMCA has informed us that no health records, diagnosis, or treatment information was impacted by this incident.

Q2.  When and how did PCHC discover this incident?

On May 15, 2019, PCHC received notice from AMCA of a possible security incident.

Q3.  How many patients were affected?

Approximately 13,000 PCHC patients were potentially affected by the AMCA breach.

Q4.  Did AMCA’s system contain information for all PCHC patients?

No. Only those PCHC patients whose accounts were sent to AMCA for debt collection may have had information on AMCA’s affected system.  PCHC systems were not affected.

Q5.  Is it safe for me to use my credit card to pay for services via phone or at a PCHC location?

Yes.  PCHC did not share your credit card information with AMCA.

Q6.  Is there a phone number I can call to receive more information or to ask question?

Yes.  Please dial 1-844-243-3018, Monday through Friday, 9:00 a.m. to 6:30 p.m., Eastern Time.

Q7.  How can I find out if my information was in AMCA’s affected system?

On July 12, 2019, PCHC mailed letters to patients who AMCA advised may have had information in their systems. Additionally, AMCA reported that it previously mailed letters to those PCHC patients who may have had credit card information in the AMCA system. You can also call 1-844-243-2018, Monday through Friday, 9:00 a.m. to 6:30 p.m. Eastern Time

Q8.  What information may have been affected?

AMCA informed us that some PCHC patients’ information may have been contained in the AMCA systems, including patients’ names, dates of birth, referring medical providers, and other medical information related to care received at PCHC. In some limited cases, PCHC patients’ credit card information may have been included. AMCA advised PCHC that no medical records, lab results, or diagnoses were involved.

Q10.  If my financial data was part of the AMCA security incident, will I receive credit monitoring to protect my accounts against unauthorized use?

PCHC has been advised by AMCA that those individuals whose credit card information was involved were offered 24 months of complimentary credit monitoring and identity theft protection services in the letter previously sent by.

Q12.  What steps has PCHC taken in response to this incident?

PCHC has ceased doing business with AMCA and is taking steps to retrieve and secure all PCHC information contained in its systems.

No related posts.

Category: Health DataSubcontractorU.S.

Post navigation

← AZ: Gila County experiences major interruption in technical service
Syracuse schools’ hit by ransomware; ransom demands increase as days go by →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • McDonald’s McHire leak involving ‘123456’ admin password exposes 64 million applicant chat records
  • Qilin claims attack on Accu Reference Medical Laboratory. It wasn’t the lab’s first data breach.
  • Louis Vuitton hit by data breach in Türkiye, over 140,000 users exposed; UK customers also affected (1)
  • Infosys McCamish Systems Enters Consent Order with Vermont DFR Over Cyber Incident
  • Obligations under Canada’s data breach notification law
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • Air Force Employee Pleads Guilty to Conspiracy to Disclose Unlawfully Classified National Defense Information
  • UK police arrest four in connection with M&S, Co-op and Harrods cyberattacks (1)
  • At U.S. request, France jails Russian basketball player Daniil Kasatkin on suspicion of ransomware conspiracy
  • Avantic Medical Lab hacked; patient data leaked by Everest Group

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • DeleteMyInfo Wins 2025 Digital Privacy Excellence Award from Internet Safety Council
  • TikTok Loses First Appeal Against £12.7M ICO Fine, Faces Second Investigation by DPC
  • German court offers EUR 5000 compensation for data breaches caused by Meta
  • How to Build on Washington’s “My Health, My Data” Act
  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.