Categories: Data Breach News InfoSec News

Data Breach at Iowa Hospital, USA – Again

Published by
RiSec.n0tst3

A data breach at an Iowa hospital has exposed the Social Security numbers and private medical information of more than 60,000 patients. 

Mercy Iowa City began notifying patients on November 13 of a data breach that occurred in spring 2020 after an employee’s email account was accessed by a threat actor. 

The hospital detected the breach on June 24 when the targeted account began sending out phishing emails and spam. An investigation revealed that the hacked account had been compromised between May 15 and June 24.

Security experts brought in to scrutinise the incident confirmed in October that sensitive patient data could have been accessed by the attacker.

Data exposed may have included names, Social Security numbers, driver’s license numbers, and health insurance information.

Chicago-based Polsinelli law firm, representing the hospital, said that 60,473 Iowa residents may have been impacted by the security incident.

In a letter sent out to affected Iowa residents on the hospital’s behalf, Bruce Radke of Polsinelli stated: “Mercy is not aware of any fraud or identity theft to any individual as a result of this incident. Nevertheless, because there was an email account compromise, Mercy searched the impacted account to determine if it contained any personal information that may have been viewed by the third party.

“Mercy determined that the compromised account contained certain personal information, including, depending on the person, their name, Social Security number, driver’s license numbers, date of birth, medical treatment information, and health insurance information.”

Mercy Iowa City is offering one year of complimentary identity theft protection services to patients whose driver’s license numbers and Social Security numbers may have been compromised.

The hospital said that it is implementing a series of cybersecurity measures including multi-factor authentication to prevent any more breaches from happening. 

“We have taken steps to reduce the risk of the type of incident occurring in the future, including enhancing our technical security measures,” said Mercy’s privacy officer, Kelli Hale.

This latest data spill is the second and worst breach to occur at Mercy Iowa City. In 2016, the acute care hospital reported a security breach that may have exposed the information of 15,625 patients. 

Cyber security is a real threat, sometimes company’s wont act until it happens over and over again. All organisations with an online presence or whom use online storage etc should have Security Audits done periodically. A cyber security audit is usually a one-day consultancy service offering a high-level cyber review of the organisation and its IT estate.

Bookmark
Please login to bookmark Close
Social Comments Box
Connect
Share the word, let's increase Cybersecurity Awareness as we know it

This post was last modified on 27 November 2020 1:22 PM

RiSec.n0tst3

Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK. I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated... I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK. I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!

Leave a Comment
Published by
RiSec.n0tst3
Tags: 60k audit data breach early 2020 Hospital Iowa patients

Recent Posts

  • Data Breach News
  • InfoSec News

WH Smith Announces Cyber-Attack: Employee Data Stolen

British high street chain WH Smith has recently revealed that it was hit by a…

2 years ago
  • InfoSec News
  • World Affairs

Voice ID: How Secure is it Really?

As banks worldwide roll out Voice ID as a means of user authentication over the…

2 years ago
  • Cybersecurity Academy
  • InfoSec News

What distinguishes Application Security from API Security?

In the era of digital transformation, cybersecurity has become a major concern for businesses. When…

2 years ago
  • Cybersecurity Academy
  • InfoSec News

The Top 5 Cybersecurity threats facing Businesses Today

In today's digital age, cybersecurity threats have become a significant concern for businesses of all…

2 years ago
  • InfoSec News
  • World Affairs

Enterprise users infected by RIG Exploit Kit thanks to Internet Explorer

The RIG Exploit Kit is currently in the midst of its most productive phase, attempting…

2 years ago
  • Cybersecurity Academy

The Rise and Rise of AI

One of the most transformational technologies of our time, artificial intelligence (AI), has quickly come…

2 years ago