[BreachExchange] Data hack at Children’s Hospital may have affected more than 3,000 families

Destry Winant destry at riskbasedsecurity.com
Wed Sep 13 22:24:05 EDT 2017


http://www.denverpost.com/2017/09/08/childrens-hospital-colorado-data-hack/

Hackers may have gained access to the personal data of more than 3,000
patient families at Children’s Hospital Colorado, the hospital in
Aurora announced Friday.

The hospital said a staff member’s email account “may have been
accessed by an unauthorized party” on July 11. After a forensic
investigation, it was determined that some of the potentially
compromised emails contained names, addresses, dates of birth and
phone numbers of patients, along with “limited clinical information,
such as diagnosis and treatment received.”

“Regrettably, this notice concerns an unintentional exposure of
protected health information that may affect nearly 3,400 patient
families,” Children’s said in its release.

The hospital said neither patient charts nor electronic medical
records systems were compromised. In addition, no Social Security
numbers or financial information was included in any of the emails.
Children’s said it has no evidence that data in the emails has been
misused or even accessed.

The hospital began informing patients of the hack on Friday and is
establishing a call center to answer questions. The center will open
Monday and can be reached at 888-398-6989 between 9 a.m. and 9 p.m. on
weekdays.

The breach at Children’s comes the same week credit reporting agency
Equifax disclosed one of the biggest data breaches in U.S. history.
The company said hackers gained access to sensitive personal data –
Social Security numbers, birth dates and home addresses – for up to
143 million Americans.


More information about the BreachExchange mailing list