DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Holy Cross Hospital Notifies Emergency Room Patients of Possible Data Breach

Posted on November 11, 2010 by Dissent

FT. LAUDERDALE (November 10, 2010) – Holy Cross Hospital announced today that it has begun sending letters to notify some of its hospital Emergency Room patients of a possible compromise of personal data from patient data sheets and to offer free credit monitoring services.

Holy Cross Hospital was informed by federal authorities that personal data from 38 Holy Cross Hospital patient data sheets had been recovered in a criminal investigation.  Working in cooperation with the U.S. Attorneys Office and U.S. Postal Inspection Service since June, Holy Cross conducted a thorough internal investigation and eventually identified an employee as the source of the data theft. The individual’s employment at the Hospital was immediately terminated.

The investigation determined that this was not a compromise of the hospital’s computer systems or network security, but involved paper copies of patient data sheets. These sheets contained basic identifying information including names, addresses, dates of birth, Social Security numbers, and brief descriptions of initial diagnosis from the Emergency Room visits.

“We place the highest priority on protecting the privacy and security of our patients’ confidential personal information,” said Dr. Patrick Taylor, President and CEO of Holy Cross Hospital.  “We expect all Holy Cross employees to reflect this institution’s strong values of caring and dedication to the welfare of our patients.  For that reason we are outraged and saddened by this former employee’s violation of that trust placed in us by our patients. We pledge to continue our full cooperation with law enforcement officials and prosecutors to ensure the administration of just punishment to all of those connected with this reprehensible act.”

At this time the hospital believes as many as 1,500 patient data sheets of Emergency Room patients may have been compromised by this employee during the period of April 2009 to September 2010.  Since it is impossible to determine the identities of all those possibly affected, the hospital is taking the extra precaution of notifying each patient that came through the Emergency Room during the period of time that the employee worked in the Emergency Room. Patients who received treatment in other hospital departments are not part of this notification and are not affected by this incident.  The process of sending out the notification letters began this morning.

“While it may be impossible to absolutely prevent an employee from violating our values and policies for personal gain, we are determined to take all necessary steps to review and strengthen our administrative procedures to ensure that we are providing the highest level of data security possible,” said Dr. Taylor.

According to Dr. Taylor, the hospital has already made a procedural change that limits the amount of key personal data included in the type of documents involved in this incident.  The hospital is also conducting a comprehensive review of its systems, policies and procedures to identify any other possible improvements.

In the letter that the affected patients will receive, Holy Cross Hospital is offering one year of free credit monitoring services from Experian to help them monitor against the possibility of identity theft and providing an information line to field patient inquiries (1-800-388-4301).

Additional information is available at www.holycrossIDprotect.com.

Source:  Holy Cross Hospital


Related:

  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident
Category: Health Data

Post navigation

← UK: Security alert over NHS data breach
NY: Town officials investigate security breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.