The Colorado Mental Health Institute at Pueblo is under the state’s Department of Human Services. On December 22, it issued a notice following discovery of a phishing incident that potentially affected 650 patients: The Colorado Mental Health Institute at Pueblo (CMHIP) experienced a potential data breach after a staff member on Nov. 1, unintentionally allowed…
Category: Health Data
SAY San Diego Provides Notice Of Data Incident
From SAY San Diego, this press release: SAY San Diego (aka Social Advocates for Youth, San Diego) became aware of an incident impacting the security of data relating to certain participants in its Dual Diagnosis youth program, from 2013, and is taking action. Although there is no indication of actual or attempted misuse of participant…
In November, I gave thanks for fewer breach reports
Protenus has released its monthly Breach Barometer, and the statistics for November were something to be thankful for – even if they turn out to be just a brief break from the crush of breach reports we’ve seen every month. As Protenus reports, there were 28 incidents first disclosed during November. We were able to…
Encryption protected Golden Optometric patients’ EHR from CrySiS attack
It’s nice to read a notification where an entity had good defenses in place. Consider this notification from Golden Optometric in California: Early on the morning of November 6, 2017, the network server at Golden Optometric was infected with a variant of the “CrySiS” ransomware virus, which encrypted a limited number of files on its…
MidMichigan notifies patients of potential breach
The Alpena News reports: MidMichigan Medical Center-Alpena notified approximately 1,900 patients last week about a potential breach of personal data, according to a press release. The information may have included patient names, addresses, social-security numbers and clinical data. The incident that gave rise to the medical center’s investigation occurred during the late evening hours of…
Attackers claim to have hacked MEDHOST (UPDATED)
Update of Dec. 23: As of this evening, the hacker has not responded to a request from this site that they provide proof of access to PHI. And according to a MedHost spokesperson, they will not be reporting this incident to HHS because no PHI was accessed. Under the circumstances, unless more emerges, DataBreaches.net is…