Tacoma’s Franciscan Health System is notifying some 8,300 patients that their personal information — including in some cases medical records and Social Security numbers — may have been shared with computer scammers who accessed staff e-mail accounts.
Those employees responded to late January phishing e-mails that appeared to be coming from Franciscan’s parent company, Catholic Health Initiatives. Those messages, composed by computer hackers, not by CHI, asked Franciscan employees to go to another site where they were to enter their e-mail user names and passwords.
While much of the information available to the scammers was routine biographical information on patients such as name, age, address and phone numbers, in some cases medical diagnoses and treatment plans were included in the records exposed to the hackers.
Franciscan spokesman Scott Thompson said the phishing expedition was a nationwide effort targeting CHI health systems’ employees. Fewer than 20 Franciscan staff members responded to those e-mail message and entered their user names and passwords.
The health system, whose Puget Sound network includes St. Joseph Medical Center in Tacoma, St. Francis Hospital in Federal Way, Highline Medical Center in Burien, St. Elizabeth Hospital in Enumclaw, St. Clare Hospital in Lakewood, St. Anthony Hospital in Gig Harbor and Harrison Hospital in Bremerton and dozens of clinics and specialty centers, said it froze those affected e-mail accounts.
The health system hired computer forensic experts to determine the extent of the data breach and to track down the perpetrators. The medical system also enlisted the FBI and the Secret Service in the investigation.
The experts spent the last two months compiling lists of those whose information was exposed to the outsiders and trying to identify the scammers.
No one has yet been arrested in the data theft. Investigators have traced the original phony e-mails to an IP address at a smaller California college, Thompson said.
Patients whose personal information was potentially compromised are receiving letters from Franciscan detailing the computer incident. Those among them whose Social Security numbers were in the data accessible to the hackers are being offered a year of free credit monitoring.
The health system has established a toll-free phone line for Franciscan patients who have questions about whether their personal information was available to the hackers. That number is 877-283-6556.
Thompson said the health system has not been notified of any incidents in which the stolen information was used to gain access patients’ bank or credit accounts or to apply for new credit in their names.
The data thieves also targeted other CHI medical employees including those of Louisville-based KentuckyOne Health and other smaller CHI health facilities across the country. Franciscan and KentuckyOne were the only health systems where more than 500 patients’ records were potentially exposed to outsiders, said the Franciscan spokesman.
Franciscan has retrained the employees who responded to the e-mail phishing effort, and the health care concern will soon be rolling out a system-wide phishing prevention update for all of its employees, the health system spokesman said.
“Franciscan Medical Group is committed to protecting patient privacy, and we deeply regret any inconvenience this incident may have caused our patients,” said Betty Doyle, regional privacy officer for Franciscan.”
