BJC Healthcare data breach, 33,000 affected

March 16, 2018

BJC HealthCare said a data storage error potentially compromised 33,420 patient records when the information was accidentally made publicly available for nine months.

BJC, based in St. Louis, said in a statement that a misconfigured server was left without a security protocol in place making it possible for someone to view scanned documents containing patient’s driver’s licenses, insurance cards, and treatment-related documents from 2003 to 2009.

Other patient data that was possibly left visible included name, address, telephone number, date of birth, Social Security number, driver’s license number, insurance information, and treatment-related inform. The server itself was left unsecure from May 9, 2017 through Jan. 23, 2018.

The issue was discovered during an internal security audit.

“The BJC investigation did not reveal that any personal data was actually accessed. Since the potential for access existed, BJC out of an abundance of caution has offered affected patients complimentary identity theft protection. BJC has implemented additional information systems processes to prevent further errors of this nature in the future,” BJC said.

SC Media has the article

Sponsored Recommendations

Enhancing Healthcare Through Strategic IT and AI Innovations

Learn how strategic IT and AI innovations are transforming healthcare - join Tomas Gregorio as he explores practical applications that enhance clinical decision-making, optimize...

The Intersection of Healthcare Compliance and Security in the Age of Deepfakes

As healthcare regulations struggle to keep up with rapid advancements in AI-driven threats like deepfakes, the security gaps have never been more concerning.

Increasing Healthcare Security Behind and Beyond the Firewall

Read how 5 identity security solutions can help you protect against these threats while improving user experience and reducing costs.

Improve and Secure Healthcare Delivery with Digital Identity

Get a deep understanding of how Digital Identity can help secure your healthcare organization while offering seamless access to your growing portfolio of apps and APIs.