Pioneer Valley Ophthalmic Consultants Hit with Malware

Over 36,000 patients had some of their protected health information exposed.

By HFT Staff


Pioneer Valley Ophthalmic Consultants (PVOC) in Holyoke, Massachusetts, has recently notified 36,275 patients that some of their protected health information has been exposed and potentially stolen in two security incidents at third-party vendors, Alta Medical Management and ECL Group, LLC, which provide billing and accounting services. 

According to the May 22, 2023, breach notice, the incidents occurred in 2021. PVOC discovered on March 3, 2022, that malware had been installed on the servers of the vendors between November 13, 2021, and November 15, 2021. On May 11, 2022, PVOC learned that Alta’s online patient portal was vulnerable to unauthorized access to payment receipts until October 26, 2021. 

The information potentially compromised as a result of the malware incident included names, addresses, Social Security Numbers, payment card information and medical records. The unsecured patient portal allowed unauthorized access to names, email addresses, transaction dates and times, transaction ID numbers, statement numbers, the last four digits of payment cards/account numbers and any information entered into the comments field of the portal. 

PVOC said it is unaware of any actual or attempted misuse of the exposed information. Monitoring has been stepped up in response to the breaches and additional technical resources and security personnel have been onboarded. Affected individuals have been offered complimentary credit monitoring services. 



June 16, 2023


Topic Area: Infection Control , Safety , Security


Recent Posts

The Fatal Flaws in Active Shooter Response in Healthcare Facilities

The most effective solutions to workplace violence are sophisticated emergency response planning and master level training for all employees.


Utah Hospital Outage Highlights Backup Power and Resiliency Challenges

The hospital went without power for nearly two hours.


Ground Broken on New North Dakota State Hospital

The 300,000-square-foot facility in Jamestown will provide 140 beds in a modern, trauma-informed care environment.


Form Your Pit Crew: Key Takeaways From the 2025 Healthcare Innovations Conference

The Healthcare Innovations Conference brought together healthcare facility managers from across the country to collaborate on industry issues.


Glens Falls Hospital Caught Up in Oracle Health Data Breach

As of November 2, 2024, Glens Falls Hospital no longer uses Oracle Health/Cerner as its electronic health record vendor.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.