DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The Coeur Group notifies patients of data breach

Posted on September 30, 2022 by Dissent

DataBreaches has not seen anything on HHS’s public breach tool, but the Coeur Group in Omaha, Nebraska, published a legal notice about a cybersecurity incident involving patient information. According to their statement, an employee’s email account in Coeur Group’s business email system was compromised between June 7 and July 12, 2022. The breach was discovered on July 26.

Only patients with information in emails or attachments in that account were potentially affected. The data for any patient might include:

Full name, demographic information (such as address and date of birth), insurance information, and clinical information (such as provider name, and limited treatment information such as diagnosis/condition and medications). For some individuals, the information also included Social Security Number and credit card information.

In response to the incident, Coeur Group took several steps, including:

reviewing access controls, implementing new authentication requirements, updating security procedures, strengthening network procedures, implementing multi-factor authentication, enhanced firewall protections, and implementing additional alerts for potential cyber threats.

Patients affected by the incident were offered one-year enrollment in an online credit monitoring service. Patients who did not receive letters or have questions can call a third-party call center at 1-855-759-3552, Monday through Friday, from 8 am – 8 pm Central Standard Time.

Coeur Group specializes in mental health issues, substance abuse disorders, and other compulsive disorders.  While those of us who report on breaches in the healthcare sector may get a bit of notice fatigue from reading so many notices, it is helpful to remember that for some situations and incidents, being exposed as a patient of a particular practice may result in some risk of stigmatization or social consequences.  The misuse of stolen information for fraud or identity theft isn’t always the most significant concern patients may have. Will any Coeur Group patients feel distressed or worry that their information was accessed or acquired by criminals who might try to extort them?

The notice does not disclose how many patients were being notified of the incident  and there is no notice on Coeur Group’s website.

Updated October 1: This incident was reported on September 23 to HHS by Cynthia Paul, M.D. as affecting 2,020 patients but was not posted on HHS’s site until after this post appeared. 

No related posts.

Category: Breach IncidentsHealth DataU.S.

Post navigation

← Data Breach at Canadian Border Agency Contractor Involved up to 1.38 Million Licence Plates
Bits ‘n Pieces (Trozos y Piezas) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns
  • One in Five Law Firms Hit by Cyberattacks Over Past 12 Months
  • U.S. Sanctions Russian Bulletproof Hosting Provider for Supporting Cybercriminals Behind Ransomware
  • Senator Chides FBI for Weak Advice on Mobile Security
  • Cl0p cybercrime gang’s data exfiltration tool found vulnerable to RCE attacks
  • Kelly Benefits updates its 2024 data breach report: impacts 550,000 customers
  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Kids are making deepfakes of each other, and laws aren’t keeping up
  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.