Skip to content Skip to navigation

Vendor Error Left 18,000 CHI Franciscan Hospital Patients’ Information Accessible Online

September 12, 2016
by Heather Landi
| Reprints

CHI Franciscan Health Highline Medical Center, based in Burien, Washington, is notifying patients of a potential data breach after a vendor partner inadvertently left files containing patient information accessible via the Internet.

According to a notice CHI Franciscan Health Highline Medical Center posted on its website, R-C Healthcare Management, a vendor working on behalf of Highline Medical Center, notified the hospital on July 22 that files containing patient information had been left accessible via the Internet by R-C Healthcare, from April 21 to June 13.

R-C Healthcare performed services for Highline Medical Center prior to CHI’s acquisition of Highline Medical Center in 2014.

According to the U.S. Department of Health and Human Services Office for Civil Rights’ breach portal website, the potential data breach was reported September 1 as “unauthorized access/disclosure” on a network server and affected 18,399 individuals.

Highline Medical Center officials wrote in the notice, “Upon notification, we immediately began an investigation and determined that the files may have contained patient name, dates of service, health insurance information and Social Security number. R-C Healthcare assured us that it has secured files as of June 13, 2016. Please note that patient medical information was not included and patient care will not be affected. We have instructed R-C Healthcare to destroy the files.”

The hospital also said the incident did not affect all patients. “It only affected patients whose data was involved in account reporting functions from years 1993-1994 and 2008-2013,” the hospital stated.

And, hospital officials also stated, “We have no knowledge that the information has been accessed, viewed, acquired or otherwise compromised by any unauthorized third party. However, out of an abundance of caution, we mailed letters to affected patients on August 31, 2016.”

CHI Franciscan Health Highline Medical Center is offering free credit monitoring services to all affected patients and established a dedicated call center to answer patients’ questions about the incident.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Trump Administration Appoints Peter Severino to Head Office for Civil Rights

Roger Severino, a former staffer at The Heritage Foundation, has been appointed as the director of the Office of Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS).

ACP: EHRs Have Great Benefits, but Raise Ethical Questions, Too

Electronic health records (EHRs) should facilitate high value patient-centered care, strong patient-physician relationships, and effective training of future physicians, but they also raise ethical questions, the ACP wrote.

Allegheny Health Network, VA Pittsburgh Integrate EMR Systems

Allegheny Health Network (AHN), based in Pittsburgh, and VA Pittsburgh Healthcare System (VAPHS), have announced the successful integration of their electronic medical record (EMR) platforms.

Wisconsin Urology Group Notifies Patients of Data Breach Due to Ransomware Attack

Wauwatosa, Wis.-based Metropolitan Urology Group has notified its patients of a breach of unsecured patient health information due to a ransomware attack back in November 2016.

Study: For Post-Op Patients, Mobile Apps for Follow-Up Care Led to Fewer In-Person Visits

For patients undergoing ambulatory surgery, those who used a mobile app for follow-up care attended fewer in-person visits post- operation than patients who did not use the app, according to a study in JAMA Surgery.

Information Blocking is Routine and Fairly Widespread, Survey of HIEs Finds

In a survey, 50 percent of HIE leaders said electronic health record (EHR) vendors "routinely" engage in information blocking, and 25 percent reported that hospitals and health systems routinely engage in business practices that interfere with electronic health information exchange.