Malicious Actor Steals Patient Data from Multiple Ernest Health Hospitals

Ernest Health, the operator of rehabilitation and long-term acute care hospitals in Arizona, California, Colorado, Idaho, Indiana, Montana, New Mexico, Ohio, South Carolina, Texas, Utah, Wisconsin, and Wyoming, has started notifying patients about a recent data security incident involving their personal and protected health information.

Ernest Health identified unauthorized activity in its computer systems on February 1, 2024, and the forensic investigation confirmed there had been unauthorized access to systems containing patient data between January 16, 2024, and February 4, 2024, and files were acquired in the attack that included patient information. For the majority of the affected individuals, the compromised data was limited to names, addresses, dates of birth, medical record numbers, health insurance plan member IDs, claims data, diagnosis, and prescription information. Some patients also had their Social Security and/or driver’s license numbers compromised.

The security incident affected patients at multiple hospitals in the network, including:

  • Advanced Care Hospital of Southern New Mexico
  • Denver Regional Rehabilitation Hospital
  • Greenwood Regional Rehabilitation Hospital
  • Lafayette Regional Rehabilitation Hospital
  • Mountain Valley Regional Rehabilitation Hospital
  • Northern Colorado Rehabilitation Hospital
  • Northern Idaho Rehabilitation Hospital
  • Northern Utah Rehabilitation Hospital
  • Rehabilitation Hospital of Southern New Mexico
  • Rehabilitation Hospital of the Northwest
  • Summa Rehabilitation Hospital
  • Trustpoint Rehabilitation Hospital of Lubbock

Notification letters started to be mailed to the affected individuals on March 29, 2024, and complimentary credit monitoring and identity theft protection services have been offered for two years. The data breach has been reported to regulators, but it is currently unclear how many patients have been affected.

The post Malicious Actor Steals Patient Data from Multiple Ernest Health Hospitals appeared first on HIPAA Journal.