DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

RI: Lifespan notifying 20,000 patients after unencrypted laptop stolen from employee’s car

Posted on April 21, 2017 by Dissent

Lifespan is committed to protecting the security and confidentiality of our patients’ information. Regrettably, this notice concerns an incident involving some of that information. To date, Lifespan has no indication that any patient information has been accessed or used by anyone as a result of this incident.

Lifespan is investigating the theft of an employee’s laptop from a car that was broken into on February 25, 2017. Several items were stolen, including a MacBook laptop used by the employee for work purposes. Upon discovering the theft, the employee immediately contacted law enforcement and reported the incident to Lifespan. Lifespan promptly began an investigation and changed the employee’s credentials used to access Lifespan system resources out of an abundance of caution.

Lifespan’s investigation determined that the MacBook was unencrypted and not password protected. The employee’s work emails stored on the MacBook were potentially accessible. Our investigation has determined that the emails may have contained patient information, including name, medical record number, demographic information such as partial address information, and the names of one or more medications that were prescribed or administered at Lifespan. The information contained in the emails did not include patient Social Security numbers or financial information, nor did it include clinical information such as diagnosis. No medical records were stored on the MacBook.

Lifespan is committed to protecting the security and confidentiality of our patients’ information, and we deeply regret this incident occurred. In order to help prevent a similar incident from reoccurring, we are re-educating our employees and enhancing our policies and procedures related to the security of MacBooks.

We began mailing letters to affected individuals on April 21 and we have established a dedicated call center to answer any questions. If you believe you may be affected and have not received a letter by May 6 or have additional questions, please call our dedicated assistance line at (877) 216-4074, Monday through Friday, between 9:00 a.m. and 7:00 p.m. Eastern Time (closed on U.S. observed holidays) and provide reference number 8866040417 when calling.

SOURCE: Lifespan

According to local media who received a press release on the matter, Lifespan is notifying 20,000 patients.


Related:

  • Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says
  • Two years after an audit highlighted significant concerns, North Salem Central School District leaves sensitive student data at risk
  • University of Pennsylvania says it wasn't hacked after a vulgar email was sent to campus community. They were wrong (1)
  • Veradigm's Breach Claims Under Scrutiny After Dark Web Leak
  • UK: Woman charged after NHS patients' records accessed in data breach
  • Landmark civil penalty of AU$5.8 million issued under Australia’s Privacy Act
Category: Health DataTheftU.S.

Post navigation

← UK: Hacker ‘caused global chaos by fuelling 1.7 million cyber attacks’
Iowa Veterans Home warns nearly 3,000 of data breach after phishing incident →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Once a Patient’s in Custody, ICE Can Be at Hospital Bedsides — But Detainees Have Rights
  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.