DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Curry Health Network notifies members of FastHealth breach

Posted on April 2, 2018 by Dissent

Last month, this site noted a FastHealth breach from 2017 that was first being disclosed.  FastHealth had reported it to HHS as impacting 1,345 patients. Now Curry Health Network is notifying its members, and it’s not totally clear if these members were included in the number that had been previously reported to HHS.  DataBreaches.net emailed FastHealth to see if they would clarify the numbers for this breach, but has received no response as yet. This post will be updated if a response is received. In the meantime, here is Curry Health Network’s notification:

(March 26, 2018) – Some community member may have received, or may be receiving, a letter from FastHealth Interactive Healthcare notifying them of a security incident. Curry Health Network has received inquiries from staff and community members regarding the legitimacy of the letter, and would like to share the following information:

FastHealth is a company with whom Curry Health Network (CHN) contracts to provide the hosting and programming for its web site. They provide these services to many hundreds of hospitals and other healthcare organizations. FastHealth stores the files which comprise the content and data submitted in forms on the CHN web site, on their servers in Alabama.

FastHealth determined, through a lengthy investigation, that an unauthorized third-party accessed their web server, and may have been able to acquire information from certain databases.

The database in question contained information submitted on the CHN employment application form, from which, again, information may or may not have been accessed. The information did not include Health Information protected by HIPAA, medical records, patient portal data, online bill pay information, or any other forms on the web site or linked to/from the web site.

FastHealth is required to notify persons who may have been affected by this unauthorized access to their server, and is in the process of sending letters to those whose information had the potential to be accessed.

FastHealth is offering one year’s identity monitoring services to all persons who receive the letter. This service includes credit monitoring, fraud consultation, and identity theft restoration.

To be clear – this incident is a FastHealth security issue; it is not a Curry Health Network security issue and does not reflect on the security of the CHN data systems. Additionally, the security of the web site does not fall under the purview of the Curry Health Network IT department, but rather to the vendor.

If you have received a letter, or receive a letter in the future, and have questions, comments or concerns, please contact the call center number included in the letter (1-833-215-3730).


Related:

  • US company with access to biggest telecom firms uncovers breach by nation-state hackers
  • Canada says hacktivists breached water and energy facilities
  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • How a hacking gang held Italy’s political elites to ransom
  • Two U.K. teenagers appear in court over Transport of London cyber attack
Category: Breach IncidentsHackHealth DataSubcontractor

Post navigation

← TX: Personal info still being discarded and dumped improperly
Equifax has been sending some consumers hit by its data breach wrong letters →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.