JUL 1, 2010 5:29pm ET

Related Links

HIT Vendor Round-up: Castlight, MedAssets & Aprima
January 31, 2012
Aetna Wants Dentists to Push Smoking Cessation via iPads
January 31, 2012
Laptop Loaded with PHI Stolen from Lexington Clinic
January 31, 2012
Consultant Describes Rocky Road Through the Health System
January 27, 2012
ONC Seeks Easy EHR Accessibility, Discharge Apps
January 26, 2012
Mostashari: 2012 Will be a Big Year for HIT
January 26, 2012
Sorting the Reform Law Options Before the Supreme Court
January 25, 2012

Web Seminars

The Evolution of Tablet Computing in Healthcare
Available On Demand
Which comes first? Chargemaster Standardization vs. System Conversion
Available On Demand
Chronic Care. Chronic I.T. Challenges
Available On Demand

FedEx Loses Disks, 130,495 Affected

Print
Reprints
Email

Overnight shipper FedEx in March lost seven CDs containing protected health information, causing Lincoln Medical and Mental Health Center in Bronx, N.Y., to recently notify 130,495 patients that their information may have been breached.

The disks, which were password protected but not encrypted, were lost while being transported to Lincoln from Siemens Medical Solutions, which performs billing and claims services for the hospital. The disks had a wide range of patient information: names, addresses, Social Security numbers, medical record numbers, patient numbers, health plan information, date of birth, dates of admission and discharge, diagnostic and procedural codes and descriptions, and some driver's license numbers.

"Please note that Lincoln has no knowledge that your protected health information, has, in fact, been improperly accessed by any person or entity," the notification letter to patients states. "Although the CDs are not protected by a form of technology that renders them unreadable, they are password protected. Furthermore, FedEx has suggested that the CDs likely became separated from their shipping envelope at one of its facilities, were swept up and destroyed."

The letter explains how to order free credit reports, place a credit alert on consumer credit files, monitor account activities to prevent fraud and monitor medical records to prevent medical identity theft. The hospital is not offering affected patients free identity theft and credit protection services, which now is a common but not universal practice.

Transportation of CDs from Siemens to Lincoln was suspended after the incident and the organizations are developing new ways to exchange the information, according to the letter.

Neither the patient letter of notification nor a public notification on the hospital's Web site mention the breach affected 130,495 patients. That number comes from a federal government Web site that lists reported breaches affecting 500 or more individuals since September 2009. More than 100 organizations now are on the list, mandated under the HITECH Act and available here.

A spokesperson for the hospital could not immediately provide additional details of the breach and reasons for not offering credit and identity protection services. To access the hospital's public notice and the patient notification letter, click here, then scroll down and click on Data Security Breach.

--Joseph Goedert

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

A major success factor for accountable care organizations will be linking caregivers across the spectrum of care delivery. If history is any indication, that's going to be an industrywide struggle.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.