DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Rotech Healthcare notifies patients whose details were found in possession of unauthorized individual

Posted on August 17, 2016 by Dissent

Rotech Healthcare Inc., a provider of home respiratory and medical equipment equipment and supplies, notified HHS of a breach involving 957 patients. Here is their notification:

Rotech Healthcare Inc. (“Rotech”) would like to notify you of a recent incident that may affect the security of your personal and protected health information. We are providing you with information regarding the incident, steps we have taken since discovering the incident and what you can do to protect against the possibility of identity theft and fraud should you feel it is appropriate to do so.

What Happened?

On June 13, 2016, Rotech received a report that certain patient information had been recovered by law enforcement after being found in the possession of an unauthorized individual. After receiving this report, Rotech immediately launched an investigation to verify the information provided and to learn more about whatmayhavehappened. Third-party forensic investigators were retained to assist with the investigationinto what happened, the identification of what information may be at risk and to whom this information relates. On July 11, 2016, the United States Secret Service provided Rotech with copies of the patient information recovered. A review of the recovered records indicates the records came from Rotech systems.

What Information Was Involved?

Although the investigations into this incident by Rotech and law enforcement are ongoing, Rotech determined that the paper records recovered by law enforcement contained your personal and protected health information, including : name, Social Security number, patient number, address, the name of the Rotech subsidiary company from which you received health care services, and possibly phone number and/or date of birth.

What We Are Doing?

Rotech takes your privacy and the security of your personal and protected health information very seriously, and we are cooperating with law enforcement’s investigation into this incident. Rotech and our third party forensic investigators continue to investigate this incident to identify any additional patients who may be impacted by this incident.

We are providing notice to all patients whose information was provided to Rotech by law enforcement and will notify any additional impacted individuals as they are identified. As part of our ongoing commitment to the security of the information in our care, we are reviewing our existing policies and procedures to better prevent something similar from happening again. We are notifying the Department of Health and Human Services and certain state regulators about this incident.

What You Can Do.

You can review the enclosed Steps You Can Take to Protect Against Identity Theft and Fraud. There you will find guidance on how to better protect against the possibility of identity theft and fraud. We know you may have questions about the content of this letter and have established a confidential, toll-free hotline to assist you with these questions and the steps you can take to better protect against the possibility of identity theft and fraud. The hotline is available Monday through Saturday, 9:00 a.m. to 9:00 p.m., EST, at 1-855-269-6650.

We sincerely regret any inconvenience this incident may cause. Rotech remains committed to safeguarding information in our care and will continue to take proactive steps to enhance the security of the information in our care.

Sincerely,

R. Wayne Bradberry, CHC
Vice President, Compliance & Ethics


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
Category: Health DataPaperU.S.

Post navigation

← Athens Orthopedic Clinic patient data still exposed on leak site
NV: Fraudulent Unemployment Claims Targeted State Employees →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.