AUG 15, 2012 5:33pm ET

Related Links

Intermountain Tracking Patients’ Cumulative Radiation Exposure
May 24, 2013
Using Analytics to Support an ‘Ambulatory ICU’ Model
May 23, 2013
University Settles with Feds After HIPAA Violations
May 22, 2013
Data Entry Error Leads to Data Breach at LSU
May 21, 2013
Consumer Groups, EHR Vendors Talk Back to GOP Senators
May 21, 2013
Rule Sets Pre-existing Coverage Rates
May 20, 2013
Medical Loss Ratio Rules Finalized for Medicare Advantage & Drug Programs
May 20, 2013

Hacker Encrypts Physicians’ Server, Demands Payment

Print
Reprints
Email

The Surgeons of Lake County, a group practice in Libertyville, Ill., recently announced a breach of protected information following an extortion attempt.

The practice discovered on June 25 that a hacker had taken control of a server hosting corporate email and electronic health records. A message on the server said its contents had been encrypted and demanded an undisclosed financial payment from the practice for a password to turn off the encryption. The practice turned off the server and it was not been turn back on, and notified authorities.

The practice has notified 7,067 patients and the HHS Office for Civil Rights, and is offering affected patients one year of credit monitoring services. Information on the server included Social Security numbers, names, addresses, credit card numbers and some medical information.

“Surgeons believes that the intention of the unauthorized access was to extort payment from Surgeons, not to take patient information, and Surgeons is not aware of any reports that the information contained on the server has been misused as a result of this incident,” according to a statement from the practice.

Comments (1)
TASCET has emphasized over and over again that healthcare organizations need to implement technology that allows those organizations to de-identify medical records. I doubt that one year of credit monitoring services would make those patients feel better...Please, look at the real solution to the problem at www.tascet.com
Posted by I S | Thursday, August 16 2012 at 5:24PM ET
Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.