Henry Ford Health System Security Breach Compromises Data of 18K Patients | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Henry Ford Health System Security Breach Compromises Data of 18K Patients

December 7, 2017
by Rajiv Leventhal
| Reprints

Henry Ford Health System in Detroit has acknowledged a data breach in which more than 18,000 patients had their personal health information compromised.

According to a breach notice posted on the health system’s website, “Henry Ford Health System is notifying 18,470 patients whose personal health information was viewed or stolen by someone who gained access to it illegally. It is not clear whether this information was used for any inappropriate purposes.”

Health system officials said that they first learned of the incident on Oct. 3 after someone gained access to or stole the email credentials— name and password protected by encryption—of a group of employees. Using the email credentials, the person would have had access to the email accounts of the employees. Contained in the email accounts were patient health information, officials said. Like other health organizations, Henry Ford providers “share encrypted email messages to ensure patient care is seamless.”

The patient information viewed or taken may have included their name, date of birth, medical record number, provider’s name, date of service, department’s name, location, medical condition and health insurer. Neither their Social Security number nor credit card information was revealed, the notice stated.

The health system said it is strengthening its security protections for employees, all of whom will be educated about this measure in the coming weeks. In addition, the organization said it is expediting its initiatives around email retention and multi-factor authentication.

Nonetheless, cybersecurity experts around the U.S. continue to question how so many of these types of breaches still occur. In an emailed statement, Clyde Hewitt, vice president of security strategy for Austin, Texas-based cybersecurity firm CynergisTek said, “It is unfortunate that members of the workforce are often the weakest link in the security chain. For decades, we have been asking them to change their passwords every 90 days or so and not to reuse old passwords, so they are harder to remember. This leads to easily guessed passwords or ones that can be guessed from their social media accounts. Healthcare providers need to move to the new model and embrace multi-factor authentication which will limit the usability of stolen credentials to a minute or two.”

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Dignity Health, CHI Merging to Form New Catholic Health System

Catholic Health Initiatives (CHI), based in Englewood, Colorado, and San Francisco-based Dignity Health officially announced they are merging and have signed a definitive agreement to combine ministries and create a new, nonprofit Catholic health system.

HHS Announces Winning Solutions in Opioid Code-a-Thon

The U.S. Department of Health and Human Services (HHS) hosted this week a first-of-its-kind two-day Code-a-Thon to use data and technology to develop new solutions to address the opioid epidemic.

In GAO Report, More Concern over VA VistA Modernization Project

A recent Government Accountability Office (GAO) report is calling into question the more than $1 billion that has been spent to modernize the Department of Veterans Affairs' (VA) health IT system.

Lawmakers Introduce Legislation Aimed at Improving Medicare ACO Program

U.S. Representatives Peter Welch (D-VT) and Rep. Diane Black (R-TN) have introduced H.R. 4580, the ACO Improvement Act of 2017 that makes changes to the Medicare accountable care organization (ACO) program.

Humana Develops Medication Management Tool

A new tool developed by Humana enables the company’s members to keep a list of their medications in one place.

Four Hospitals Piloting OurNotes Initiative in 2018

Beginning in January, four academic hospitals—Beth Israel Deaconess Medical Center in Boston, University of Washington in Seattle, Dartmouth-Hitchcock Medical Center in Lebanon, New Hampshire and University of Colorado in Boulder—will begin piloting a new digital tool called OurNotes that enables patients to contribute to their clinical notes.