Geisinger notified over a million patients after a vendor insider breach

Organization
Geisinger
Exploit
Third-Party Data Breach
Industry
Healthcare

Geisinger, the Pennsylvania health system, issued public notice on June 24, 2024 that patient information had been improperly accessed by a former employee of Nuance Communications, an information technology vendor it used.

According to Geisinger, the individual accessed Geisinger patient records on November 27, 2023, two days after Nuance terminated him. Geisinger identified the activity on November 29 and alerted Nuance, which shut down the accounts the same day. Public notification was held back until June at the request of law enforcement while a criminal investigation proceeded.

Geisinger said the records involved names in combination with one or more of the following: date of birth, address, admission and discharge or transfer code, medical record number, race, gender, telephone number and a facility name abbreviation. It stated that no claims or insurance information, credit card or bank account numbers, other financial information, or Social Security numbers were inappropriately accessed. The health system said more than one million patients were potentially affected. The figure later reported to federal regulators was 1,276,026.

The former Nuance employee, identified in court filings as Andre J. Burk, also known as Max Vance, was arrested and charged federally. Geisinger set up a dedicated telephone line and advised patients to review health plan statements for services they did not receive. Class action litigation against Geisinger and Nuance was later settled for $5 million.

Sources