Conifer hack compromises patient data from 6 hospitals

2022-08-16
Dallas-based Conifer Revenue Cycle Solutions, which manages revenue and administrative services for healthcare providers, announced on August 12 that it had been hacked on January 20. The cyberattacker was able to access patient information associated with six hospitals. WHY IT MATTERS Conifer says it learned of the breach in April. After a cybersecurity review of the compromised Microsoft Office 365-hosted email account, the company informed affected Texas patients from San Antonio-based Baptist Health System; Resolute Health Hospital in New Braunfels; The Hospitals of Providence Memorial Campus in El Paso and Valley Baptist Medical Centers in Brownsville and Harlingen. The vendor sent a separate notice to Alabama patients on behalf of Brookwood Baptist Medical Center in Birmingham. Conifer's officials said the type of patient data compromised may have included identification information (such as full name, date of birth and home address), social security number, driver’s license/state ID number and/or financial account information, medical and/or treatment information (such as medical record number, dates of service, provider and facility, diagnosis or symptom information and prescriptions) and health insurance and billing information. "In response to this incident, Conifer immediately took action to block malicious IP addresses and URLs," the company said. "In addition, the password for the impacted account was reset shortly after the unauthorized access. Conifer has enhanced and continues to enhance its security controls and monitoring practices as appropriate to minimize the risk of any similar incident in the future, and Conifer accelerated its implementation of multi-factor authentication for business email accounts within the environment." THE LARGER TREND Cybersecurity breaches of healthcare organizations pose the highest costs of any industry and require some of the lengthiest reviews to identify and contain security incidents. Since January, there have been more than 400 incidents of cybersecurity breaches of unsecured protected health information affecting more than 500 people, according to the U.S. Department of Health and Human Services Office for Civil Rights case investigation list . The majority of incidents list network server and email breaches. The Conifer breach affected 2,787 patients, according to OCR. ON THE RECORD "Based on a detailed review conducted between June 13, 2022 and August 3, 2022, it was determined that your personal information associated with a healthcare provider was in the impacted business email account," the Conifer statement said. Andrea Fox is senior editor of Healthcare IT News. Email: afox@himss.org Healthcare IT News is a HIMSS publication.
更多内容,请访问原始网站
文中所述内容并不反映新药情报库及其所属公司任何意见及观点,如有版权侵扰或错误之处,请及时联系我们,我们会在24小时内配合处理。
适应症
-
靶点
-
药物
-
立即开始免费试用!
智慧芽新药情报库是智慧芽专为生命科学人士构建的基于AI的创新药情报平台,助您全方位提升您的研发与决策效率。
立即开始数据试用!
智慧芽新药库数据也通过智慧芽数据服务平台,以API或者数据包形式对外开放,助您更加充分利用智慧芽新药情报信息。