Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 19th, 2011, 18:52 GMT · By

Stolen Spartanburg Regional Computer Contains 400k Patient Records

SHARE:

Adjust text size:


Spartanburg Regional loses 400k patient records
Enlarge picture
Spartanburg Regional, a South Carolina healthcare system, has been notifying 400,000 of current and former patients that their personal information was compromised when one of the organization's computers was stolen.

According to the healthcare provider, the theft occurred on March 29, 2011, when a desktop computer was stolen from an employee's car overnight.

"The employee was authorized to have possession of the computer. We have reported this to the proper authorities and an investigation is ongoing," Spartanburg Regional said.

The computer contained 400,000 patient records that included real names, addresses, dates of birth and medical billing codes. Spartanburg doesn't mention if the computer was password protected or if the data was encrypted.

The security rule of the Health Insurance Portability and Accountability Act (HIPAA), which protects medical records, states that encryption is optional if the data is stored on a closed system or network with adequate physical and technical protection.

However, the breach notification rule says that "individual notifications must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach."

Considering the theft occurred at the end of March, Spartanburg might be in violation of the HIPAA provisions. However, given the unusually high number of letters that needed to be sent, the organization might have received an extension.

Spartanburg offers affected individuals a free subscription with an identity theft protection service provided by Kroll which includes credit monitoring, as well as identity theft consultation and restoration.

"We regret that this incident occurred. We encourage you to take advantage of these services, which are provided at no cost to you. If you have any questions at all, please call 1-855-401-2640, 9:00 a.m. to 6:00 p.m. (Easern Time), Monday through Friday," Spartanburg wrote in its letter.

TELL US WHAT YOU THINK:

1,325 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


FedEx Loses CDs Containing NY Hospital's Patient Data

WellPoint Sued by the State of Indiana over Late Breach Notification

HHS Issues First HIPAA Civil Penalty - $4.3 Million

HHS to Receive $1 Million from Mass General for HIPAA Violations

University of California Settles HIPAA Violations for $865K

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM