25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Five Rivers Health Centers Phishing Attack Affects Almost 156,000 Patients

Ohio-based Five Rivers Health Centers has notified 155,748 patients that some of their protected health information was stored in email accounts that have been accessed by an unauthorized individual following a phishing attack.

It is unclear when the breach was discovered, but Five Rivers Health Centers reports that following an extensive forensic investigation into the cyberattack and a manual document review, it discovered on March 31, 2021, that the breached email accounts contained patients’ personal and health information.

The forensic investigation confirmed that the email accounts had been breached between April 1, 2020, and June 2, 2020. Notification letters were sent to affected patients on May 28, 2021 – More than a year after the first email accounts were breached.

The types of protected health information in emails and attachments varied from patient to patient and may have included one or more of the following data elements:  Name, address, date of birth, medical record number, patient account number, diagnoses, treatment and/or clinical information, test results, lab test reports, provider name, dates of service, treatment cost information, prescription information, health insurance information, and Medicaid or Medicare numbers.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

A limited number of individuals also had their financial account number, payment card numbers, driver’s license number, state identification number, and/or Social Security number exposed. A 12-month complimentary membership to a credit monitoring service has been offered to individuals whose Social Security number was exposed.

Following the attack, policies and procedures have been reviewed and updated, 2-factor authentication has been implemented, and employees have been provided with further cybersecurity training.

Cancer Centers of Southwest Oklahoma Breach Affects 8,000 Patients

Cancer Centers of Southwest Oklahoma (CCSO) has discovered the protected health information of 8,000 patients was potentially compromised in a cyberattack on one of its business associates. CCSO used a 1st generation cloud-based storage system provided by Elekta Inc., which was breached earlier this year.

Elekta hired third-party cybersecurity experts to investigate the security breach and confirmed on April 28, 2021, that the breached systems included the protected health information of CCSO patients. While it was not possible to determine what information was accessed or exfiltrated by the attackers, Elekta concluded that all information in the system had been exposed and must be considered compromised. The cloud-based storage system remains offline while the forensic investigation continues.

CCSO said in its substitute breach notification letter that the following types of information were stored in the system and may have been accessed or stolen: Name, Social Security number, address, date of birth, height, weight, medical diagnosis, medical treatment details and appointment confirmations.

Elekta is offering complimentary access to identity monitoring, fraud consultation, and identity theft restoration services to affected individuals.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist