DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CommonSpirit Gets Restraining Order in Missing Patient Info Suit (UPDATED)

Posted on December 28, 2022 by Dissent

Holly Barker reports:

CommonSpirit Health, one of the country’s largest nonprofit health systems, convinced a federal judge in Texas to order a medical technology vendor to return hundreds of thousands of medical records it was sent to archive.

The US District Court for the Northern District of Texas’s order directs Emerge Clinical Solutions LLC to return all protected health information and other data in its possession; verify the destruction of all PHI and other data that can’t be returned; and complete and return the “Certificate of Return or Destruction of Protected Health Information,” in accordance with the parties’ agreement.

Read more at Bloomberg Law (sub. req.)

Looking at the court filings, it appears that CommonSpirit had a business associate agreement with Emerge Clinical Solutions to perform some projects for them. In late September, CommonSpirit found that there were some data extraction errors in Kentucky made by Emerge and sought their correction. According to the court filing:

Plaintiff immediately contacted Defendant to request that Defendant correct the errors. Defendant initially and generally responded to Plaintiff’s concerns on September 28, 2022. This was the last contact between Plaintiff and Defendant, despite Plaintiff’s continued efforts.

Plaintiff has made attempts to reach out to its contacts with Defendant and all such attempts have been unsuccessful. Further, the general phone line listed on Defendant’s website has been disconnected.

Upon information and belief, Defendant stopped paying its employees and contractors in September of 2022.

Emerge allegedly was in possession of files on hundreds of thousands of patients. CommonSpirit sought an injunction from the court, whose order noted that Emerge never responded by the deadline the court had imposed.

It is not clear whether this problem with Emerge had any bearing at all on recovery from the ransomware attack CommonSpirit experienced. DataBreaches has sent an inquiry to CommonSpirit asking them whether this was a totally unrelated situation, but no reply has been received as yet.

Update: CommonSpirit sent the following statement:

CommonSpirit hired Emerge Clinical Solutions to perform certain Information Technology support services. When Emerge failed to respond to our inquiries regarding its safekeeping of certain CommonSpirit data, CommonSpirit sought an injunction for return or destruction of that data.

At this time, we have no reason to believe any data has been subject to any unauthorized access, use or disclosure, and the majority of records entrusted to Emerge have been successfully returned.

This incident is unrelated to the recent cyberattack experienced by CommonSpirit Health.


Related:

  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Theft from Glasgow’s Queen Elizabeth University Hospital sparks probe
  • North Country Healthcare responds to Stormous's claims of a breach
Category: Health DataSubcontractor

Post navigation

← Updating Scripps Health ransomware incident: litigation settlement
Double trouble for JAKKS Pacific: double locked by two ransomware groups →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance
  • Wiretap Suits Pit Old Privacy Laws Against New AI Technology
  • Action against tiny Scottish charity sparks huge ICO row
  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.