Sharp HealthCare notified about 63,000 patients after a web server breach
- Organization
- Sharp HealthCare
- Exploit
- Hacking
- Industry
- Healthcare
Sharp HealthCare, San Diego's largest health system, began notifying 62,777 patients in early February 2023 that some of their information had been exposed when an unauthorised party reached a web server hosting sharp.com.
The intrusion took place on January 12, 2023 and lasted only a few hours, during which the attacker retrieved a file connected to the provider's online bill payment service. Patients who paid a bill or invoice through that service between August 12, 2021 and January 12, 2023 were affected.
The file contained patient names, internal Sharp identification numbers and invoice numbers, payment amounts, and the names of the Sharp entities receiving the payments. Sharp said the incident did not involve bank account or credit card details, Social Security numbers, contact information, dates of birth, health insurance information, clinical records or details of the care patients received. Its medical record systems and the FollowMyHealth patient portal were not affected.
Sharp said it had no indication that anyone's information had been misused. It added security tooling to its web servers, began mailing notification letters on February 3, 2023, and opened a dedicated toll-free line for patients with questions.