MedStar Health Victim of Data Security Incident

The nonprofit healthcare provider experienced the breaches intermittently between January 2023 and October 2023.

By HFT Staff


On May 3, 2024, MedStar Health mailed notification letters to certain patients whose personal information may have been involved in a data incident. 

They discovered that an outside party had accessed emails and files associated with three MedStar Health employee email accounts. The unauthorized access occurred intermittently between January 25, 2023, and October 18, 2023. On March 6, 2024, after conducting a forensic analysis of the unauthorized access, they determined that patient information was included in the emails and files accessed. While they have no reason to believe patient information was acquired or viewed, MedStar Health cannot rule out such access. 

The emails and files contained information that may have included some or all the following: patients’ names, mailing address, dates of birth, date(s) of service, provider name(s) and/or health insurance information.  

Patients whose information may have been involved are encouraged to review statements they receive related to their healthcare. If they identify anything unusual related to the healthcare services or the charges for services, they should contact the healthcare entity or health insurer immediately. 

MedStar Health has employed appropriate physical, technical and administrative controls to ensure the safety and confidentiality of patients’ information. Nonetheless, to help prevent something like this from happening again, they have implemented additional safeguards and security measures to enhance their existing controls. They have also notified law enforcement. 



May 9, 2024


Topic Area: Information Technology , Security


Recent Posts

ISSA Introduces Healthcare Platform to Advance Safer, Cleaner Patient Environments

This new resource integrates training, research and cross-sector collaboration to raise care standards and improve patient outcomes.


Third-Party Tracking Settlement is a Compliance Wake-Up Call for Healthcare Facilities Managers

Mount Sinai Health System agrees to a $5.3 million settlement to resolve claims it improperly shared patient data with Facebook through tracking tools.


ECU Health Behavioral Health Hospital Hosts Ribbon-Cutting Ceremony for New Facility

The new facility features 144 beds and a healing environment for behavioral health patients.


Aspire Rural Health System Reports Data Security Incident

Upon detecting the unauthorized activity, Aspire immediately worked to contain the incident and launched a thorough investigation.


Fatal Flaws: Strategies for Active Attackers

Anything that goes wrong with the response is the liability exposure of the organization — not the employee and not the police.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.