DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Washington University School of Medicine notifies patients of HIPAA breach

Posted on November 2, 2019 by Dissent

Washington University School of Medicine in St. Louis  issued this notice on Nov. 1:

Washington University School of Medicine announced today that it began mailing letters to patients whose information may have been involved in a recent security incident at its Department of Ophthalmology and Visual Sciences.

On Sept. 3, 2019, the School of Medicine learned that a small number of patients had received a letter regarding an ophthalmology department employee. The School of Medicine quickly began an internal investigation and determined that the letter was sent by an individual who knew the employee. The unauthorized individual took the employee’s personal laptop and used it to access the employee’s School of Medicine email account between April 29 and Sept. 3, 2019. The School of Medicine immediately took steps to secure the employee’s email account, and a leading computer forensic firm was engaged to assist with our continued investigation.

The investigation was not able to determine which, if any, emails or attachments in the employee’s email account were viewed by the unauthorized individual. The School of Medicine, therefore, conducted a review of the emails and attachments contained in the email account to identify patient information that may have been in the account. As a result of that review, on Oct. 21, 2019, the School of Medicine determined that emails or attachments in the account contained patient information, which may have included patient names, dates of birth, medical record numbers, and limited treatment and/or clinical information, such as diagnoses, provider names, and/or prescription information. In some instances, patients’ health insurance information and/or Social Security numbers were also included in the account.

This incident did not affect all School of Medicine patients, but only those ophthalmology department patients who had information contained in the affected email account.

The School of Medicine is mailing letters to patients whose information was found in the account and has established a dedicated, toll-free call center to answer any questions individuals may have about the incident. Patients with questions can call the call center at (844) 996-1023, Monday through Friday from 8 a.m. to 5:30 p.m. central time. For any School of Medicine patient whose Social Security number was contained in the email account, the School of Medicine is offering complimentary credit monitoring and identity protection services. The School of Medicine also recommends that affected patients review statements they receive from their health insurers or healthcare providers. If they see charges for services not received, they should contact the insurer or provider immediately.

To help prevent something like this from happening in the future, the School of Medicine has reinforced education with its staff on best practices for passwords, and are making additional security enhancements.

Information about the security incident also is posted on the School of Medicine’s website and is available by clicking this link.

The notice to patients, available on their site, is a bit more specific and makes clear that the unauthorized individual is someone who had had a personal relationship with the employee.

Category: HackHealth DataU.S.

Post navigation

← Hackers can steal the contents of Horde webmail inboxes with one click
Brooklyn Hospital Center notifies patients after data could be not be recovered after malware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Rewards for Justice offers $10M reward for info on RedLine developer or RedLine’s use by foreign governments
  • New evidence links long-running hacking group to Indian government
  • Zaporizhzhia Cyber ​​Police Exposes Hacker Who Caused Millions in Losses to Victims by Mining Cryptocurrency
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Google: Hackers target Salesforce accounts in data extortion attacks
  • The US Grid Attack Looming on the Horizon
  • US govt login portal could be one cyberattack away from collapse, say auditors
  • Two Men Sentenced to Prison for Aggravated Identity Theft and Computer Hacking Crimes
  • 100,000 UK taxpayer accounts hit in £47m phishing attack on HMRC
  • CISA Alert: Updated Guidance on Play Ransomware

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector
  • U.S. Enacts Take It Down Act
  • 23andMe Bankruptcy Judge Ponders Trump Bill’s Injunction Impact
  • Hell No: The ODNI Wants to Make it Easier for the Government to Buy Your Data Without Warrant
  • US State Dept. says silence or anonymity on social media is suspicious

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.