How do you make a data breach even worse? You notify the victims that they are dead.
The headline says it all:
The situation started routinely enough — an employee’s email account was compromised. In this case, the access was used to send out spam.
Somehow, however, in the process of sending breach notifications, there was a mail merge error. As Saint Alphonsus explained:
We have learned that some of our patients have received a letter notifying them of an email security event and unfortunately, when the letters were generated, a mail merge issue created an incorrect status for some patients, addressing them as deceased or a minor.
So first an employee’s email account gets compromised and then their vendor has a screw-up. It was not a great month for the hospital, it seems.