BreachExchange mailing list archives

Security Breach at Erlanger Health System has Families Upset


From: Erica Absetz <erica () riskbasedsecurity com>
Date: Mon, 8 Apr 2013 12:24:34 -0400

http://www.wdef.com/news/story/Security-Breach-at-Erlanger-Health-System-has/dF_wE2QwdUKWmNoq2KnHDw.cspx

87 families received notification from Erlanger Health System, saying
their child's medical records were found outside the hospital.

We caught up with one of the families affected by phone.

Shane Wright says, "This information included his name, address, phone
number, diagnosis."

And even his social security number.

Erlanger says an incident happened on or around January 14th of this year.

They tell us they are working with local law enforcement officers and
security experts right now to figure out more.

Wright adds, "I think we felt as though an organization of that
magnitude should have more precautionary measures in place to prevent
such malicious activity from occuring."

In Erlanger's letter to Wright, it says in order to prevent this from
happening again, they have enhanced physical security and security
training for their staff.

Wright adds, "I also think Erlanger should educate their employees on
identity fraud, just make sure they're aware of how detrimental this
could be potentially to one's personal lives by allowing information
to get into the wrong hands."

The Wright's say they have already contacted an attorney because they
want to protect their child's identity.

In the meantime, they will wait on more answers from Erlanger.

Wright says, "If this was not an accident, we just hope that those who
are in the wrong are brought to justice."

Erlanger tells us to date, they are unaware of any suspicious or
unauthorized use of any information.
_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: