DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The Coeur Group notifies patients of data breach

Posted on September 30, 2022 by Dissent

DataBreaches has not seen anything on HHS’s public breach tool, but the Coeur Group in Omaha, Nebraska, published a legal notice about a cybersecurity incident involving patient information. According to their statement, an employee’s email account in Coeur Group’s business email system was compromised between June 7 and July 12, 2022. The breach was discovered on July 26.

Only patients with information in emails or attachments in that account were potentially affected. The data for any patient might include:

Full name, demographic information (such as address and date of birth), insurance information, and clinical information (such as provider name, and limited treatment information such as diagnosis/condition and medications). For some individuals, the information also included Social Security Number and credit card information.

In response to the incident, Coeur Group took several steps, including:

reviewing access controls, implementing new authentication requirements, updating security procedures, strengthening network procedures, implementing multi-factor authentication, enhanced firewall protections, and implementing additional alerts for potential cyber threats.

Patients affected by the incident were offered one-year enrollment in an online credit monitoring service. Patients who did not receive letters or have questions can call a third-party call center at 1-855-759-3552, Monday through Friday, from 8 am – 8 pm Central Standard Time.

Coeur Group specializes in mental health issues, substance abuse disorders, and other compulsive disorders.  While those of us who report on breaches in the healthcare sector may get a bit of notice fatigue from reading so many notices, it is helpful to remember that for some situations and incidents, being exposed as a patient of a particular practice may result in some risk of stigmatization or social consequences.  The misuse of stolen information for fraud or identity theft isn’t always the most significant concern patients may have. Will any Coeur Group patients feel distressed or worry that their information was accessed or acquired by criminals who might try to extort them?

The notice does not disclose how many patients were being notified of the incident  and there is no notice on Coeur Group’s website.

Updated October 1: This incident was reported on September 23 to HHS by Cynthia Paul, M.D. as affecting 2,020 patients but was not posted on HHS’s site until after this post appeared. 

Category: Breach IncidentsHealth DataU.S.

Post navigation

← Data Breach at Canadian Border Agency Contractor Involved up to 1.38 Million Licence Plates
Bits ‘n Pieces (Trozos y Piezas) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.