DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Houston doctor's office vandalized, patient data on stolen hard drive

Posted on March 2, 2012 by Dissent

A media/substitute notice:

The office building and office suite of Jeremiah J. Twomey M.D., was vandalized during the weekend of December 31, 2011, at which time an external drive containing personal and confidential health information of individuals was stolen from Dr. Twomey’s office. Unauthorized use of this data is unlikely. Any individuals who believe they may have been affected by this incident are asked to please contact the response team of ID Experts at 1-877-283-6561.

The independent investigation indicated that names, addresses, medical conditions, diagnoses and, in some instances, Social Security numbers and dates of birth, were contained on the stolen hard drive. Dr. Twomey has encrypted all data that is maintained electronically to ensure that personal and confidential health information is stored and handled in a secure manner. Individuals with questions regarding this incident can visit http://www.jjtwomeymd.com/index.htm .

In addition to procedural changes, Dr. Twomey has contracted with ID Experts® to provide an extensive level of services to protect individuals from personal and medical identity theft. These services include: a one year FraudStop(TM) Healthcare Edition membership that provides fraud resolution services, education materials, insurance reimbursement for expenses related to resolve an identity theft situation; and a Healthcare Identity Protection Toolkit(TM) with comprehensive information and resources on medical identity theft.

This press release is in accordance with the Health Information Technology for Economic and Clinical Health (HITECH) Act and the Health Insurance Portability and Accountability Act(HIPAA). The medical offices of Jeremiah J. Twomey, M.D., F.A.C.P. has notified potentially affected individuals, clients, and the Department of Health and Human Services (HHS).

For Press Only:Jeremiah Twomey, M.D., F.A.C.P.1-877-283-6561

SOURCE ID Experts

“Unauthorized use of this data is unlikely.” is the second sentence in the notice? Seriously, ID Experts? You should know better.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident
  • Heritage Provider Network $49.99M Class Action Settlement
  • Integris Health Agrees to $30 Million Settlement Over 2023 Data Breach
Category: Health Data

Post navigation

← More Sites Hacked and Defaced for #FreeTibet
UK: North cop faces data protection breach charges →

4 thoughts on “Houston doctor's office vandalized, patient data on stolen hard drive”

  1. Anonymous says:
    March 7, 2012 at 4:36 pm

    If my medical card from the insurance company has my name and member id on it… is that considered PHI?

    1. Anonymous says:
      March 7, 2012 at 6:16 pm

      If that info is held by a HIPAA-covered entity or business associate, yes, as far as I know.

  2. Anonymous says:
    March 8, 2012 at 6:18 pm

    ““Unauthorized use of this data is unlikely.” is the second sentence in the notice? Seriously, ID Experts? You should know better.”

    Well, the information *was* encrypted (from the description, it sounds like full disk encryption)….maybe they should have mentioned that in the same sentence. I must admit I was taken a little aback when I read that same passage, encryption or no encryption.

    1. Anonymous says:
      March 8, 2012 at 7:23 pm

      There’s encryption and then there’s encryption. If the data or disk were encrypted to NIST standards, there would be no mandatory notification. Since they’re notifying, I made the assumption that this is not to NIST standards. I could be wrong of course, but…

      In any event, whenever an entity starts out by minimizing risk, it makes it less likely that recipients will take action to protect themselves. And as study after study have shown, people who receive breach notices are more than 4 times as likely to become victims of ID theft within the next year or so. So yeah, I don’t like seeing entities minimize – especially right off the top.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.