UC Irvine Medical Center announced data breach when one of its employee viewed thousands of patient records over a four-year period which not included in the job-related purpose. The incident potentially compromised the information of 4,859 patients.
The affected information includes names, dates of birth, gender, medical record numbers, height, weight, medical center account numbers, allergy information, home address, medical documentation, diagnoses, test orders and results, medications, employment status, and the names of patient’s health plans and employers. However, Social Security numbers, driver’s licenses or state ID card numbers, and credit or debit card information were not accessed.
Hospital spokesperson John Murray mentioned that there is no evidence that the records were downloaded or distributed via e-mail. A copy of notification letters being sent to patients was posted on the California Office of Attorney General website. UC Irvine explained the reason behind the notification letters.
“Due to its on-going investigation, local law enforcement asked us not to notify patients right away, because sending out notifications could have interfered with its investigation. Local law enforcement has now informed us that we are free to notify patients.”
The notification letter also mentioned that the hospital has hired independent experts to conduct a thorough investigation. Also, affected patients will also be offered one year of free credit monitoring and identity theft protection.
Get your personal as well as office laptops encrypted by Alertsec
Unencrypted laptops present a major risk of data loss. 80% of information theft is due to lost or stolen laptops and other equipment. About 50% of network intrusions are performed with credentials gathered from lost or stolen devices. The penalties for a data breach are severe not only in terms of the monetary fines imposed on the organization, but also the potential loss of trust from customers and suppliers. Encryption software greatly enhances the security of your organization’s data as the information is not compromised if a laptop is lost or stolen.
Alertsec Xpress is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.