DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Washington University School of Medicine notifies patients of HIPAA breach

Posted on November 2, 2019 by Dissent

Washington University School of Medicine in St. Louis  issued this notice on Nov. 1:

Washington University School of Medicine announced today that it began mailing letters to patients whose information may have been involved in a recent security incident at its Department of Ophthalmology and Visual Sciences.

On Sept. 3, 2019, the School of Medicine learned that a small number of patients had received a letter regarding an ophthalmology department employee. The School of Medicine quickly began an internal investigation and determined that the letter was sent by an individual who knew the employee. The unauthorized individual took the employee’s personal laptop and used it to access the employee’s School of Medicine email account between April 29 and Sept. 3, 2019. The School of Medicine immediately took steps to secure the employee’s email account, and a leading computer forensic firm was engaged to assist with our continued investigation.

The investigation was not able to determine which, if any, emails or attachments in the employee’s email account were viewed by the unauthorized individual. The School of Medicine, therefore, conducted a review of the emails and attachments contained in the email account to identify patient information that may have been in the account. As a result of that review, on Oct. 21, 2019, the School of Medicine determined that emails or attachments in the account contained patient information, which may have included patient names, dates of birth, medical record numbers, and limited treatment and/or clinical information, such as diagnoses, provider names, and/or prescription information. In some instances, patients’ health insurance information and/or Social Security numbers were also included in the account.

This incident did not affect all School of Medicine patients, but only those ophthalmology department patients who had information contained in the affected email account.

The School of Medicine is mailing letters to patients whose information was found in the account and has established a dedicated, toll-free call center to answer any questions individuals may have about the incident. Patients with questions can call the call center at (844) 996-1023, Monday through Friday from 8 a.m. to 5:30 p.m. central time. For any School of Medicine patient whose Social Security number was contained in the email account, the School of Medicine is offering complimentary credit monitoring and identity protection services. The School of Medicine also recommends that affected patients review statements they receive from their health insurers or healthcare providers. If they see charges for services not received, they should contact the insurer or provider immediately.

To help prevent something like this from happening in the future, the School of Medicine has reinforced education with its staff on best practices for passwords, and are making additional security enhancements.

Information about the security incident also is posted on the School of Medicine’s website and is available by clicking this link.

The notice to patients, available on their site, is a bit more specific and makes clear that the unauthorized individual is someone who had had a personal relationship with the employee.


Related:

  • Hacking Formula 1: Accessing Max Verstappen's passport and PII through FIA bugs
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Hotel and Casino near Las Vegas Strip suffers data breach, documents say
  • Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
Category: HackHealth DataU.S.

Post navigation

← Hackers can steal the contents of Horde webmail inboxes with one click
Brooklyn Hospital Center notifies patients after data could be not be recovered after malware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.