Gryphon Healthcare Notifies 400,000 Patients About Recent Cyberattack
Gryphon Healthcare has recently confirmed a security incident involving unauthorized access to files containing the protected health information (PHI) of almost 400,000 individuals. Gryphon Healthcare is a Houston, TX-based provider of revenue cycle, coding, compliance, consultancy, and management services to healthcare providers such as hospitals, EMS providers, emergency departments, independent labs, medical imaging centers, ambulatory surgery centers, and physician practices.
The security incident occurred at a partner for whom Gryphon Healthcare provides medical billing services. Gryphon Healthcare learned about the third-party incident on August 13, 2024, and following a comprehensive review of the affected files determined that the PHI of 393,358 patients of its healthcare clients had been exposed and potentially obtained by an unauthorized individual. Further information on the nature of the attack, such as whether ransomware was involved, was not disclosed. It is also unclear how many of its healthcare provider clients were affected.
The file review was completed on September 3, 2024, and confirmed that the exposed data includes names, addresses, dates of birth, dates of service, Social Security numbers, diagnoses, health insurance information, medical treatment information, prescription information, provider information, and medical record numbers. Gryphon Healthcare said it had found no evidence at the time of issuing notifications that any of the affected PHI has been misused; however, “out of an abundance of caution”, the affected individuals have been offered complimentary identity theft protection services. The services include credit and CyberScan monitoring, identity theft recovery services, and a $1 million identity theft insurance policy.
Gryphon Healthcare said it has implemented measures to enhance security and minimize the risk of a similar incident occurring in the future. Notification letters were mailed to the affected individuals on October 11, 2024. The delay between the completion of the file review and the issuing of notification letters was due to the time taken to verify contact information for the affected individuals.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy


