HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

Tandigm Health Website Vulnerability Exposed 7,000 Patients’ PHI

A vulnerability on a website used by the value-based healthcare company Tandigm Health could potentially have been exploited to gain access to patients’ protected health information.

The website vulnerability was discovered by Tandigm Health on September 25, 2018. A leading computer forensics firm assisted with the investigation to determine whether the flaw could be exploited remotely, whether patients’ protected health information had been accessed, and the types of information that may have been exposed.

The investigation confirmed that the flaw could have been exploited to gain access to sensitive patient information between April 24, 2017 and December 31, 2017. The information accessible through the website was limited to names, birth dates, medical information, and health insurance information. Approximately 7,000 patients’ protected health information was accessible through the website.

The investigation did not uncover any evidence to suggest the flaw had been exploited and no reports been received to suggest patient information has been stolen or misused.

Please see the HIPAA Journal Privacy Policy

3 Steps To HIPAA Compliance

Please see HIPAA Journal
privacy policy

  • Step 1 : Download Checklist.
  • Step 2 : Review Your Business.
  • Step 3 : Get Compliant!

The HIPAA Journal compliance checklist provides the top priorities for your organization to become fully HIPAA compliant.

Out of an abundance of caution, all individuals whose personal and health information were exposed have been notified of the potential breach by mail and have been offered free credit monitoring and identity theft protection services for 2 years.

Affected individuals have been advised to monitor their accounts and credit reports for any sign of unauthorized transactions and to review explanation of benefits statements from their health insurers for any medical services that have been listed but not received.

According to a company press release, “Information privacy and security are among Tandigm’s highest priorities, and there are strict security measures in place to protect information in Tandigm’s care.”

Tandigm Health has reassessed its website protections and has enhanced security on its Internet-based platforms. Current policies and procedures covering data security have been reviewed and additional, ongoing data security training is being provided to employees.

Author: Steve Alder is the editor-in-chief of HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered on HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has several years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics.