DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

St. Mary’s Hospital Campus in Jefferson City notifies 301,000 of limited PHI left behind in a 2014 move

Posted on August 7, 2018 by Dissent

And this is why I always wait to close out monthly stats in healthcare.  The following incident just showed up on HHS’s public breach tool today as having been reported to them on July 30, and affecting 301,000 patients. St. Mary’s Hospital’s notice, below, indicates that the entity was not sure of the number affected. 

JEFFERSON CITY, MO – On June 1, 2018, SSM Health St. Mary’s Hospital – Jefferson City was notified that documents and other materials containing patient information were discovered in isolated locations at the former hospital campus, while it was being readied for demolition. Upon notification, SSM Health promptly secured the information and launched an immediate investigation.

St. Mary’s Hospital has confirmed that all formal medical records were safely and securely transferred prior to the move to the new facility on November 16, 2014. The type of information located at the old facility largely consisted of administrative and operational supporting documents for various departments. The documents included demographic, financial, and/or clinical data, but in most instances involved very limited information such as name or medical record number alone. A comprehensive review of the recovered information is underway, and the hospital has also retained a document services firm to assist in cataloging all recovered documents.

Although at all times security safeguards and deterrents were in place to protect the facility, the investigation has confirmed that the safeguards were not adequate to ensure the security of the patient information and other materials with absolute confidence between the date of the move until the date that the hospital was notified on June 1, 2018.  For this reason, we are notifying affected individuals out of an abundance of caution.  Given the age and type of information recovered, the hospital does not yet have a reliable estimate of the number of individuals impacted, however it’s actively working to identify every patient whose information has been recovered.

With the recovery of the patient information, SSM Health feels that this incident does not represent a significant risk to patients, however, it does constitute a privacy breach under Health Insurance Portability and Accountability Act (HIPAA). The Office for Civil Rights has been notified, and St. Mary’s is in the process of sending notification letters containing additional information to the impacted patients who can be identified and located.

The hospital is also reviewing and revising its policies and procedures regarding proper record storage, retention and destruction, as necessary. “We are taking immediate steps to resolve this situation and prevent something similar from ever happening again,” said Phil Gustafson, interim regional president of Operations, SSM Health of Mid-Missouri. “We take very seriously our role of safeguarding our patients’ personal information, and deeply regret any inconvenience or concern this situation may cause our patients.”

If patients have additional questions, they can call toll-free 1-888-648-8404 to get more information.

###

SOURCE: SSM Health St. Mary’s Hospital – Jefferson City


Related:

  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Inquiry launched after identities of SAS soldiers leaked in fresh data breach
  • Michigan ‘ATM jackpotting’: Florida men allegedly forced machines to dispense $107K
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
  • Government will 'robustly defend' compensation claims from Afghans put at risk by data breach
Category: ExposureHealth DataPaperU.S.

Post navigation

← FCC admits it was never actually hacked
Telemedicine company exposed data of more than 2 millions patients in Mexico →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance
  • Wiretap Suits Pit Old Privacy Laws Against New AI Technology
  • Action against tiny Scottish charity sparks huge ICO row
  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.