BREAKING: Massive Cyber Attack at Banner Health Affects 3.7M Individuals | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

BREAKING: Massive Cyber Attack at Banner Health Affects 3.7M Individuals

August 3, 2016
by Rajiv Leventhal
| Reprints

Phoenix-based Banner Health, one of the largest healthcare systems in the U.S., announced on August 3 that it is notifying approximately 3.7 million individuals about a breach in which cyber attackers gained unauthorized access to computer systems that process payment card data at food and beverage outlets at certain Banner locations.

The incident was discovered by Banner Health on July 7, though the attack was initiated on June 17, according to the health system’s press release. The attackers targeted payment card data, including cardholder name, card number, expiration date and internal verification code, as the data was being routed through affected payment processing systems. Payment cards used at food and beverage outlets at certain Banner Health locations during the two-week period between June 23 and July 7 may have been affected. The investigation revealed that the attack did not affect payment card payments used to pay for medical services, the organization said.

Then, on July 13, Banner Health learned that the cyber attackers may have indeed gained unauthorized access to patient information, health plan member and beneficiary information, as well as information about physician and healthcare providers. The patient and health plan information may have included names, birthdates, addresses, physicians’ names, dates of service, claims information, and possibly health insurance information and social security numbers, if provided to Banner Health. The physician and provider information may have included names, addresses, dates of birth, social security numbers and other identifiers they may use.

How the hack expanded from certain food and beverage outlets to patient information systems is currently unclear. But, Banner has mailed letters to 3.7 million patients, health plan members and beneficiaries, food and beverage customers and physicians and healthcare providers related to  the attack.

The health system said that it “worked quickly to block the attackers and is working to enhance the security of its systems in order to help prevent this from happening in the future.” Banner is also working with the payment card networks so banks that issue payment cards can be made aware and initiate heightened monitoring on the affected cards.

Banner Health is offering a free one-year membership in monitoring services to patients, health plan members, health plan beneficiaries, physicians and healthcare providers, and food and beverage customers who were affected by this incident.

The health system owns and operates 29 acute care hospitals, Banner Health Network, Banner University Medicine, Banner Medical Group, long-term care centers, outpatient surgery centers and an array of other services, including family clinics, home care and hospice services, pharmacies and a nursing registry. Banner Health is spread throughout seven states: Alaska, Arizona, California, Colorado, Nebraska, Nevada and Wyoming

“Banner is committed to maintaining the privacy and security of information of our patients, employees, plan members and beneficiaries, customers at our food and beverage outlets, as well as our providers,” Peter S. Fine, Banner Health president and CEO, said in a statement.

Healthcare Informatics will continue to update this story as it unfolds.

 

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

White House Proposes Restructuring, Renaming HHS as Part of Broad Reorganization Plan

A sweeping government reorganization plan released by the White House Thursday proposes restructuring and renaming HHS, including moving many public assistance programs from USDA to HHS.

CMS Introduces Data Element Library

The Centers for Medicare & Medicaid Services (CMS) has announced the launch of its Data Element Library (DEL), with the overarching goal to support the exchange of electronic health information.

Data Breach at Health Billing Company Exposes PHI of 270,000 People

A healthcare data breach at Med Associates, a Lathan, N.Y.-based health billing company, that may have exposed the protected health information (PHI) of 270,000 people, according to local media reports.

CMS to Host Blue Button 2.0 Developer Conference

The Centers for Medicare & Medicaid Services will host the first Blue Button 2.0 Developer Conference at the General Services Administration national headquarters in Washington, D.C., on Monday, Aug. 13, 2018.

House Passes Bill to Align HIPAA, 42 CFR Part 2

The U.S. House of Representatives recently passed a bill designed to align 42 CFR Part 2 with HIPAA for the purposes of health care treatment, payment, and operations. One goal of the change is so that care can be better coordinated and providers can have appropriate access to all of a patient’s medical record, including information about substance use disorders.

MedStar Health Awarded Grant to Pilot Apps for Patient-Reported Outcome Data

A team of researchers from Maryland-based MedStar Health has been awarded an 18-month contract from AHRQ to support the development and testing of technical tools and apps that can be used to collect patient-reported outcome data.