Hack of Appointment System at Emory Healthcare Affects 80,000 Patient Records | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Hack of Appointment System at Emory Healthcare Affects 80,000 Patient Records

March 3, 2017
by Heather Landi
| Reprints

Atlanta-based Emory Healthcare has reported that in January a hacker demanded a ransom after accessing one of the health system’s appointment systems and deleting the appointment information database. The hack affected the records of about 80,000 patients.

In a statement posted on its website, Emory Healthcare said it’s Orthopaedics & Spine Center and Brain Health Center within Emory Clinic used an application called Waits & Delays to update patients regarding their appointments. “This database contained limited information used in updating appointment information including patients’ names, dates of birth, contact information, internal medical record numbers, and basic appointment information such as dates of service, physician names and whether patients required imaging (but not the type of imaging). The database did not contain patients’ Social Security numbers, financial information, diagnosis or other electronic medical record information,” the health system stated.

On January 3, 2017, the health system learned that there was unauthorized access to the appointment system around the New Year’s weekend after someone deleted the database and demanded a ransom to restore it.

“We learned that there was another unauthorized access by an independent security research center that searches out vulnerabilities in applications and traditionally notifies the company so that it can be remedied. Once EHC learned that this third-party database was accessed improperly, we immediately initiated an internal investigation, alerted law enforcement and are in the process of notifying impacted patients. Additionally, we are taking this opportunity to further review and refine our security measures relating to internal and third-party computer systems,” the health system stated.

According to the U.S. Department of Health and Human Services Office for Civil Rights (OCR) data breach portal, the Emory Healthcare breach was submitted on Feb. 21 and affected 79,930 people and was categorized as “hacking/IT incident.”

Emory Healthcare has reported that, currently, there is no indication that any patient information has been used inappropriately.

The incident impacted patients who either had an appointment at the Orthopaedics & Spine Center within Emory Clinic between March 25, 2015 and January 3, 2017, or had an appointment at the Emory Clinic Brain Health Center between December 6, 2016 and January 3, 2017.

 

 

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Study: EHRs Tied with Lower Hospital Mortality, But Only After Systems Have Matured

Over the past decade, there has been significant national investment in electronic health record (EHR) systems at U.S. hospitals, which was expected to result in improved quality and efficiency of care. However, evidence linking EHR adoption to better care is mixed, according to medical researchers.

Nursing Notes Can Help Predict ICU Survival, Study Finds

Researchers at the University of Waterloo in Ontario have found that sentiments in healthcare providers’ nursing notes can be good indicators of whether intensive care unit (ICU) patients will survive.

Health Catalyst Completes Acquisition of HIE Technology Company Medicity

Salt Lake City-based Health Catalyst, a data analytics company, has completed its acquisition of Medicity, a developer of health information exchange (HIE) technology, and the deal adds data exchange capabilities to Health Catalyst’s data, analytics and decision support solutions.

Advocate Aurora Health, Foxconn Plan Employee Wellness, “Smart City,” and Precision Medicine Collaboration

Wisconsin-based Advocate Aurora Health is partnering with Foxconn Health Technology Business Group, a Taiwanese company, to develop new technology-driven healthcare services and tools.

Healthcare Data Breach Costs Remain Highest at $408 Per Record

The cost of a data breach for healthcare organizations continues to rise, from $380 per record last year to $408 per record this year, as the healthcare industry also continues to incur the highest cost for data breaches compared to any other industry, according to a new study from IBM Security and the Ponemon Institute.

Morris Leaves ONC to Lead VA Office of Electronic Health Record Modernization

Genevieve Morris, who has been detailed to the U.S. Department of Veterans Affairs (VA) from her position as the principal deputy national coordinator for the Department of Health and Human Services, will move over full time to lead the newly establishment VA Office of Electronic Health Record Modernization.