MA hospital data breach

June 27th, 2016 by admin Leave a reply »

Massachusetts General Hospital (MA) suffered potential data breach when some dental practice patients may have been affected by the hacking incident. It involved third party vendor that provides dental practice information management software.

As per the statement,  “Massachusetts General Hospital (MGH) is deeply committed to the security and confidentiality of our patients’ information, including any such information maintained by our third-party vendors. Regrettably, this notice concerns an incident involving some of that information.”

Vendor found out that unauthorized entities had gained access to its systems. It exposed some of the hospital’s patient files. Probable accessed information included names, dates of birth, Social Security numbers, medical record numbers, dates and types of dental appointments, and dental provider names.

MA mentioned that the attackers did not access any of its systems or any files managed by the hospital. Vendor Patterson Dental Supply Inc contacted local law enforcement officials. Investigation is initiated for the hacking event and law enforcement officials have asked MA to withhold notifying potentially affected patients. It also stopped them from releasing a public statement until the investigation was over.

Later on 26 may, the hospital got the necessary permission to contact impacted individuals. It  then mailed notification letters to all affected patients on June 29. Call centre is also created to answer the query related to the incident. The statement did not mention the number of affected individuals.

“We are committed to the security of sensitive information maintained by our third-party vendors and are taking this matter very seriously,” explained the statement. “To help prevent this type of incident from happening again, PDSI [Patterson Dental Supply Inc] took steps to enhance the security of its systems that maintain dental practice data.”

————————————————————————————————————————————————————–

Alertsec is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your or
ganization.

Leave a Reply