Elitecare Emergency Hospital notifies 24,754 patients of data breach
- Organization
- Elitecare Emergency Hospital
- Exploit
- Hacking
- Industry
- Healthcare
Elitecare Emergency Hospital, which runs 24 hour adult emergency and pediatric urgent care services in League City, Texas, told 24,754 patients that their information had been exposed in a network intrusion. Staff noticed suspicious activity on the hospital's computer systems on July 10, 2024 and disconnected them the same day.
Third party cybersecurity specialists were brought in to investigate and law enforcement was notified. By July 17, 2024 the hospital had confirmed that an unauthorized party had reached files containing protected health information.
What was exposed varied by patient. The categories included names, addresses, dates of birth, phone numbers and email addresses, along with health insurance details such as plan, member and group identifiers and Medicaid or other government payor numbers. Medical record numbers, treating providers, diagnoses, medications, test results and treatment details were also involved, as were billing, claims and payment records and, for some patients, Social Security numbers and driver's license or state identification numbers.
Elitecare reported the breach to the U.S. Department of Health and Human Services Office for Civil Rights in September 2024 and began mailing notification letters. It said it had reinforced its security policies with additional technical safeguards, was monitoring the internet and dark web for signs the data had been published, and offered affected patients two years of credit monitoring and identity theft protection. It reported no evidence of misuse at the time notifications went out.