St. Luke's Health System Experiences Data Breach

The data breach was the result of sending certain letters to an incorrect mailing address.

By HFT Staff


On March 6, 2023, St. Luke’s Health System discovered a technical error that resulted in certain letters mailed on Feb. 17 and Feb. 24 to be inadvertently sent to the incorrect mailing address. St. Luke’s immediately began investigating the cause of this error and implementing safeguards to prevent future occurrences. This error has been corrected, and there is no indication at this time to suggest that there has been any attempt to misuse patient information. Individuals who received another individual’s letter because of this error are asked to please destroy the letter.    

These letters included the guarantor’s name, guarantor number, patient’s name, date of service, encounter-specific account number, outstanding balance and balance status.   

Upon learning of this issue, St. Luke’s immediately began investigating the cause of this error. They have addressed the cause of this error and have implemented additional safeguards to prevent this error from happening in the future. In addition, impacted individuals’ accounts have been reset to provide additional time to resolve their balances. Their accounts are not in collections, and they are not accountable for the balances in the incorrect letter.   

In addition, St. Luke’s is offering identity theft protection services through IDX, the data breach and recovery services expert. IDX identity protection services include: 12 months of credit and CyberScan monitoring, a $1 million insurance reimbursement policy, and fully managed identity theft recovery services. With this protection, IDX will help resolve issues if an identity is compromised. 



April 17, 2023


Topic Area: Security


Recent Posts

The HVAC Dilemma: To Repair or Replace?

Healthcare facilities that keep repairing and optimizing aging systems past their useful life spend money on a problem they cannot solve without capital investment.


Department of Veterans Affairs Signs Lease for Community-Based Outpatient Clinic in Kentucky

Construction and facility preparation are expected to be completed by the winter of 2027, and the first patient should be seen by spring 2028.


Cameron Regional Medical Center Falls Victim to Ransomware Attack

CRMC is not currently aware of any evidence to suggest that any information has been fraudulently misused.


3 Pillars of Stronger Cybersecurity in Healthcare

These strategies can help healthcare facilities stay ahead of evolving cyber threats.


Meridian Acquires Medical Office Building in Pasadena, CA

The property was acquired for approximately $13.35 million.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.