An old database that seems to have magically reappeared online more than a decade after it was removed reminds us of an often-overlooked risk. In January, DataBreaches.net reported that a behavior intervention therapist’s database was exposed online due to a misconfigured MongoDB installation. What struck me about the incident was that the therapist likely had no idea that a company she had…
Category: Health Data
CA: Anesthesiologist notifies patients after PHI wound up in a trash container
Anesthesiologist Pratap S. Kurra, M.D., is notifying some of his patients whose protected health information was found to have been discarded improperly on August 8. In a template of the notification letter uploaded to the California Attorney General’s web site, Dr. Kurra writes: On August 9, 2016, I was informed that papers related to my…
RI: University Gastroenterology notifies patients of ransomware attack
University Gastroenterology is notifying patients after what sounds like a ransomware attack. In a notice on their web site, they write that on July 11, 2016, they discovered that an unauthorized individual had gained access to an electronic file storage system from a practice they had acquired in 2014, Consultants in Gastroenterology, and encrypted several files….
CA: Yuba-Sutter Medical Clinic discloses August ransomware attack
Yuba-Sutter Medical Clinic is notifying patients after a ransomware attack on August 3. Fortunately, the center was able to regain access relatively quickly and no data were lost, although they acknowledge that they did experience some delays in accessing internal information and patient information while they worked to regain access. As far as they can…
Incident response shouldn’t include threatening the media, Saturday edition
As I commented to someone recently, a security incident involving Appalachian Regional Hospital facilities in Beckley and Summers County struck me as a really serious one because it was impacting patient care. While ARH responded promptly and initiated its emergency operations plan after detecting that its system was infected, it seemed clear that shifting to an…
OR: Asante Notifies Patients of Inappropriate File Access by Employee
The following is a press release: Asante announced today that it is notifying individuals related to a privacy incident involving certain patient information. On July 13, 2016, Asante determined that an employee had inappropriately accessed certain electronic patient records. Asante immediately began an investigation related to this incident and the specific employee, which was completed on July…