Skip to content Skip to navigation

Arizona Pain Clinic Notifies 900K Patients, Providers and Employees about Information Security Incident

August 17, 2016
by Heather Landi
| Reprints
Click To View Gallery

Phoenix-based Valley Anesthesiology and Pain Consultants is notifying 882,592 patients and all current and former employees and providers about an information security incident due to a third party possibly gaining unauthorized access to its computer systems.

The pain clinic, which is comprised of 300 anesthesiology and interventional pain management providers, posted a notice on its website regarding an incident involving patient information. According to that notice, on June 13, 2016, Valley Anesthesiology and Pain Consultants (VAPC) learned that a third party may have gained unauthorized access to the VAPC computer systems on March 30, 2016. “Upon learning of the situation, VAPC immediately began an investigation, including hiring a leading forensic firm, and notifying law enforcement,” the notice stated.

“The forensics firm found no evidence that the information on the computer system was accessed, but was unable to definitely rule that out,” the notice stated.

According to a press release that VAPC released August 12 about the same security incident, the computer systems may contain patient information, such as patient names, their providers' names, dates of service, places of treatment, names of health insurers, insurance identification numbers, diagnosis and treatment codes, and in some instances, social security numbers.

For providers, the computer systems included credentialing information, such as names, dates of birth, social security numbers, professional license numbers, Drug Enforcement Agency (DEA) numbers, National Provider Identifiers (NPIs), as well as bank account information and potentially other financial information. For employees, the computer systems included names, dates of birth, addresses, social security numbers, bank account information and financial information, such as tax information.

The pain clinic also said that there is no evidence that any patient information was accessed or used inappropriately.

VAPC also stated in the press release that the organization is taking steps to enhance the security of its computer systems in order to prevent this type of incident from occurring again in the future. These steps include reviewing its security processes, strengthening its network firewalls, and continuing to incorporate best practices in IT security.

The pain clinic also is offering free credit monitoring and identity protection services to those individuals whose social security numbers or Medicare numbers were included in the incident.



CMS Hospital Compare Website Updated with VA Data

The Centers for Medicare & Medicaid Services (CMS) has announced the inclusion of Veterans Administration (VA) hospital performance data as part of the federal agency’s Hospital Compare website.

CMS Awards Funding to Special Innovation Projects

The Centers for Medicare & Medicaid Services (CMS) has awarded 20, two-year Special Innovation Projects (SIPs) aimed at local efforts to deliver better care at lower cost.

Center of Excellence in Genomic Science to be Established in Chicago

The National Human Genome Research Institute has awarded $10.6 million over five years for the establishment of a new research center in Chicago to advance genomic science.

EHNAC and HITRUST Combine HIPAA Security Criteria, CSF Framework

The Electronic Healthcare Network Accreditation Commission (EHNAC) and the Health Information Trust Alliance (HITRUST) announced plans to streamline their accreditation and certification programs.

Halamka on MACRA Final Rule: “CMS is Listening and I Thank Them”

Health IT notable expert John Halamka, M.D., CIO of Beth Israel Deaconess Medical Center in Boston, recently weighed in on the Medicare Access and CHIP Reauthorization Act (MACRA) final rule.

Texas Patient Care Clinic Hit with Ransomware Attack

Grand Prairie, Texas-based Rainbow Children's Clinic was the victim of a ransomware attack on its IT systems in August, affecting more than 33,000 patients, according to multiple news media reports this week.