DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CommonSpirit Gets Restraining Order in Missing Patient Info Suit (UPDATED)

Posted on December 28, 2022 by Dissent

Holly Barker reports:

CommonSpirit Health, one of the country’s largest nonprofit health systems, convinced a federal judge in Texas to order a medical technology vendor to return hundreds of thousands of medical records it was sent to archive.

The US District Court for the Northern District of Texas’s order directs Emerge Clinical Solutions LLC to return all protected health information and other data in its possession; verify the destruction of all PHI and other data that can’t be returned; and complete and return the “Certificate of Return or Destruction of Protected Health Information,” in accordance with the parties’ agreement.

Read more at Bloomberg Law (sub. req.)

Looking at the court filings, it appears that CommonSpirit had a business associate agreement with Emerge Clinical Solutions to perform some projects for them. In late September, CommonSpirit found that there were some data extraction errors in Kentucky made by Emerge and sought their correction. According to the court filing:

Plaintiff immediately contacted Defendant to request that Defendant correct the errors. Defendant initially and generally responded to Plaintiff’s concerns on September 28, 2022. This was the last contact between Plaintiff and Defendant, despite Plaintiff’s continued efforts.

Plaintiff has made attempts to reach out to its contacts with Defendant and all such attempts have been unsuccessful. Further, the general phone line listed on Defendant’s website has been disconnected.

Upon information and belief, Defendant stopped paying its employees and contractors in September of 2022.

Emerge allegedly was in possession of files on hundreds of thousands of patients. CommonSpirit sought an injunction from the court, whose order noted that Emerge never responded by the deadline the court had imposed.

It is not clear whether this problem with Emerge had any bearing at all on recovery from the ransomware attack CommonSpirit experienced. DataBreaches has sent an inquiry to CommonSpirit asking them whether this was a totally unrelated situation, but no reply has been received as yet.

Update: CommonSpirit sent the following statement:

CommonSpirit hired Emerge Clinical Solutions to perform certain Information Technology support services. When Emerge failed to respond to our inquiries regarding its safekeeping of certain CommonSpirit data, CommonSpirit sought an injunction for return or destruction of that data.

At this time, we have no reason to believe any data has been subject to any unauthorized access, use or disclosure, and the majority of records entrusted to Emerge have been successfully returned.

This incident is unrelated to the recent cyberattack experienced by CommonSpirit Health.

Category: Health DataSubcontractor

Post navigation

← Updating Scripps Health ransomware incident: litigation settlement
Double trouble for JAKKS Pacific: double locked by two ransomware groups →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.