DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Sutter Health East Bay Region reports breach after police uncover patient information during investigation

Posted on June 9, 2013 by Dissent

Sutter Health East Bay Region is notifying patients of a breach they first learned about on May 23.

According to their letter, a copy of which was provided to the California Attorney General’s Office, on May 23, they were notified by the Alameda County Sheriff’s Office that patient information had been discovered as part of an investigation. The information included patients’ names, date of birth, Social Security number, address and zip code, gender, marital status, home and work phone numbers, and place of employment.

As of this week, Sutter was unsure which facilities the patient data had been stolen from or how. Nor do they indicate whether these were copies of actual patient records and if the information was in electronic or paper format.

Affected patients were offered free credit monitoring, and given the types of information involved and the fact that it showed up in the context of a criminal investigation, I’d say that patients should definitely avail themselves of the offer and remain vigilant in checking and protecting their credit.

The Sutter Health East Bay Region covers Alameda and Contra Costa counties with three medical centers – Alta Bates Summit, Eden and Sutter Delta- spread across six campuses, plus a medical foundation of physicians at care centers located throughout the East Bay Region.

Sutter has been named in a number of high-profile breaches and is still facing a class action lawsuit stemming from this large breach.

UPDATE: KTVU has more on the new breach:

The personal information of nearly 5,000 patients at three Bay Area hospitals may have been stolen and authorities only found out about because of a drug bust in Oakland almost a month ago.

Sutter Health East Bay region notified the public Friday that 4,500 patients had personal information taken from the hospital.

The information which isn’t medical may include Social Security number, employer, address and birth date.

Read more on KTVU.  A statement on Sutter’s site says:

Law Enforcement Finds List of East Bay Patients

Posted on Jun 7, 2013

The Alameda County Sheriff’s Department recently notified one of Sutter Health’s hospitals in the East Bay that during an unrelated investigation it recovered information pertaining to approximately 4,500 people.

We do not know what law enforcement was investigating when they obtained this information. The information may have originated from Sutter Health’s Alta Bates Summit, Sutter Delta or Eden medical centers, and may have included a patient’s name, Social Security number, date of birth, gender, address, zip code, home phone number, marital status, name of employer and work phone number.

While it is presently unclear where the information originated, we have notified the patients whose information was potentially involved and are offering them free credit monitoring services. We have also alerted the appropriate government agencies.

We are concerned about this matter and take protecting our patients’ privacy very seriously. At this time we do not know how the information was obtained. We continue to cooperate with law enforcement to investigate this incident.

If you are a patient and think you have been affected, please call 1-888-414-8020, Monday through Friday, 8:00 a.m. to 5:00 p.m. Pacific Time.  When prompted, enter the following ten digit reference number: 2789053113.


Related:

  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident
Category: Health Data

Post navigation

← HHS updates its breach tool
Inland Valleys IPA members notified by SynerMed of breach involving their PHI →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.