DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Washington University School of Medicine notifies patients of HIPAA breach

Posted on November 2, 2019 by Dissent

Washington University School of Medicine in St. Louis  issued this notice on Nov. 1:

Washington University School of Medicine announced today that it began mailing letters to patients whose information may have been involved in a recent security incident at its Department of Ophthalmology and Visual Sciences.

On Sept. 3, 2019, the School of Medicine learned that a small number of patients had received a letter regarding an ophthalmology department employee. The School of Medicine quickly began an internal investigation and determined that the letter was sent by an individual who knew the employee. The unauthorized individual took the employee’s personal laptop and used it to access the employee’s School of Medicine email account between April 29 and Sept. 3, 2019. The School of Medicine immediately took steps to secure the employee’s email account, and a leading computer forensic firm was engaged to assist with our continued investigation.

The investigation was not able to determine which, if any, emails or attachments in the employee’s email account were viewed by the unauthorized individual. The School of Medicine, therefore, conducted a review of the emails and attachments contained in the email account to identify patient information that may have been in the account. As a result of that review, on Oct. 21, 2019, the School of Medicine determined that emails or attachments in the account contained patient information, which may have included patient names, dates of birth, medical record numbers, and limited treatment and/or clinical information, such as diagnoses, provider names, and/or prescription information. In some instances, patients’ health insurance information and/or Social Security numbers were also included in the account.

This incident did not affect all School of Medicine patients, but only those ophthalmology department patients who had information contained in the affected email account.

The School of Medicine is mailing letters to patients whose information was found in the account and has established a dedicated, toll-free call center to answer any questions individuals may have about the incident. Patients with questions can call the call center at (844) 996-1023, Monday through Friday from 8 a.m. to 5:30 p.m. central time. For any School of Medicine patient whose Social Security number was contained in the email account, the School of Medicine is offering complimentary credit monitoring and identity protection services. The School of Medicine also recommends that affected patients review statements they receive from their health insurers or healthcare providers. If they see charges for services not received, they should contact the insurer or provider immediately.

To help prevent something like this from happening in the future, the School of Medicine has reinforced education with its staff on best practices for passwords, and are making additional security enhancements.

Information about the security incident also is posted on the School of Medicine’s website and is available by clicking this link.

The notice to patients, available on their site, is a bit more specific and makes clear that the unauthorized individual is someone who had had a personal relationship with the employee.


Related:

  • Hacking Formula 1: Accessing Max Verstappen's passport and PII through FIA bugs
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Hotel and Casino near Las Vegas Strip suffers data breach, documents say
  • Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
Category: HackHealth DataU.S.

Post navigation

← Hackers can steal the contents of Horde webmail inboxes with one click
Brooklyn Hospital Center notifies patients after data could be not be recovered after malware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Russian hackers target IVF clinics across UK used by thousands of couples
  • US, allies sanction Russian bulletproof hosting services for ransomware support
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • Large medical lab in South Africa suffers multiple data breaches
  • Report released on PowerSchool cyber attack
  • Sue The Hackers – Google Sues Over Phishing as a Service
  • Princeton University Data Breach Impacts Alumni, Students, Employees
  • Eurofiber admits crooks swiped data from French unit after cyberattack
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Closing the Privacy Gap: HIPRA Targets Health Apps and Wearables
  • Researchers claim ‘largest leak ever’ after uncovering WhatsApp enumeration flaw
  • CIPL Publishes Discussion Paper Comparing U.S. State Privacy Law Definitions of Personal Data and Sensitive Data
  • India’s Digital Personal Data Protection Act 2023 brought into force
  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.