Skip to main content
Back
Mercy Medical Center Redding

Mercy Medical Center Redding Data Breach (2014)

Mercy Medical Center Redding

lowVERIS
Disclosed

December 13, 2014

4122 days ago

Records

620

Confirmed

Root Cause

Human Error

Industry

Healthcare

Description

About 620 North State Dignity Health patients personal information was accessible online for several weeks, the organization reported Monday. A third party, contracted for transcriptions of physician notes at Dignity Health Mercy Oncology Center, accidentally made public a link to some notes stored on a private server during a routine update, said Patrick Varga, Mercy Medical Centers chief operating officer. The records are no longer public, Varga said. On Dec. 13, a physician reviewing patient records discovered the link, he said. About 620 patients, who sought care June through October, have been affected, Nichols said. The records included the patients names, dates of birth, diagnosis, medications, therapies and treatment plans, she said. They did not contain any Social Security numbers or financial information. The link was removed immediately, and Mercy is working with Google to scrub any other links or archived versions of the web page, Varga said. Mercy no longer contracts with the company. Verga said there are no signs that any unauthorized individuals accessed the information, which was public for several weeks. The leak is a protocol breach rather than a cyber security threat, said Rocky Slaughter, whose public relations company, Sugar Pine Media, designs websites. The chances of the patients exposure is small. As long as the information isnt posted on another server, or posted on Reddit (or other type of) social media, I think people will be OK, Slaughter said. Google has a content removal process, he said. Mercy also has been educating staff and its contractors on securing medical information, Varga said. It has contacted all patients affected and provided them with recommendations on how they can protect themselves from identity theft. Mercy Medical Center takes confidentiality of patient information very serious, he said.

Mercy Medical Center Redding Data Breach (2014) - 620 Records | ExposedMap