Midwest Spine And Brain Institute (MSBI) is writing with important information regarding a network security incident involving its third-party provider, 3C Care Systems, LLC (“3C”).
MSBI recently learned that its third-party MSP provider, 3C, was affected by an external cyberattack. 3C is a healthcare IT company specializing in workflow automation and augmentation solutions.
Upon learning of the issues with 3C, MSBI immediately opened an investigation with the assistance of external professional experienced in handling these types of incidents to assist MSBI with an investigation and to assess the full scope of information impacted. 3C also conducted an independent, external forensic investigation with the assistance of cybersecurity professionals. At this time, MSBI can confirm there was no compromise to its larger network due to this incident.
MSBI’s review determined that the potentially impacted information included first and last names with one or more of the following identifiers: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service and health insurance claim and/or policy information.
The investigation is still ongoing. As such, MSBI has not confirmed whose personal information may have been impacted. However, in general, the potentially impacted information could include protected health information (PHI) and personally identifiable information (PII). The types of impacted information varied by individual and not all of these data elements were impacted for each individual.
How Retail Design Principles Can Improve Healthcare Wayfinding
Flexible Design Strategies Help OhioHealth Maximize Clinical Space
What Accessibility in Senior Care Facilities Should Look Like
Corewell Health to Expand Grand Rapids and Troy Hospitals