The breach of a supplier's database may have left the personal information of as many as 2.65 million patients of Atrium Health exposed to hackers, according to a statement released on Tuesday. Atrium Health operates 44 hospitals across North Carolina, South Carolina, and Georgia.
AccuDoc, a company that prepares bills and operates the website where Atrium Health patients can make payments online, became aware that a cyber incident took place on Oct. 1. According to the release, an "unauthorized third party" accessed the patient information between Sept. 22 and Sept. 29. Logs indicate that information was not downloaded, AccuDoc noted.
The information accessed includes first and last names, home addresses, dates of birth, insurance policy information, medical record numbers, invoice numbers, account balances, and dates of service. For roughly 700,000 patients, the accessed information may also include their Social Security numbers.
According to the release, AccuDoc immediately shut down unauthorized access to the database. Both AccuDoc and Atrium Health say they are conducting internal forensics reviews and have contacted the FBI.
Black Hat Europe returns to London Dec 3-6 2018 with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.