Mass General Brigham fired staff who let outsiders view patient records

Organization
Mass General Brigham
Exploit
Malicious Insider
Industry
Healthcare

Mass General Brigham disclosed in late June 2024 that employees at the Massachusetts health system and at its insurance arm, Mass General Brigham Health Plan, had allowed individuals who did not work for the organisation to carry out parts of their jobs, giving those outsiders access to patient and member information.

The health system said it identified the activity in early April 2024 and completed its investigation on May 28. Two Mass General Brigham employees were found to have permitted unauthorised access between February 26 and April 4, 2024. Separately, a Mass General Brigham Health Plan employee allowed an unauthorised person to handle member information between July 31, 2023 and April 2, 2024. Three employees were terminated.

The information that may have been viewed included names, addresses, dates of birth, medical record numbers, telephone numbers, email addresses, health insurance policy numbers and clinical details such as reasons for visits, diagnoses and admission dates. A smaller set of records also included Social Security numbers and payment card numbers.

Two reports were filed with the U.S. Department of Health and Human Services Office for Civil Rights on June 28, 2024, one covering 3,659 health plan members and another covering 655 individuals. Mass General Brigham offered those affected 24 months of credit monitoring and identity theft protection, and said it had strengthened employee training and the processes behind its security alerting.

Sources