AUSTIN — Seton Family of Hospitals, a division of Seton Healthcare Family, recently sent letters to approximately 39,000 individuals regarding an email phishing attack that targeted the email accounts of its employees.
Sophisticated hackers gained access to protected health information contained in employee email accounts through a fraudulent email. Some patient health information was accessed, including demographic information (i.e., name, address, gender, date of birth, etc.), medical record numbers, insurance information, limited medical information and, in some cases, Social Security numbers.
Usernames and passwords for the email accounts were immediately shut down and Seton launched a thorough investigation. Computer experts were able to conduct an analysis of information contained in the affected email accounts, determine the scope of the incident and identify all the individuals affected. Email “phishing” continues to occur and increase across the globe. It is a paramount concern for Seton and other healthcare providers, which are entrusted with some very personal information by their patients.
“We value the privacy and security of protected information, and we are committed to protecting the confidentiality and privacy of our patients and employees,” said Jesús Garza, Seton Healthcare Family president and chief executive officer. “It is our priority to support those who have been affected.”
Seton will provide free identity monitoring and protection services, as appropriate, for individuals whose Social Security numbers were compromised.
Affected individuals may call 1-888-687-9294, Monday through Friday, 8 a.m. to 6 p.m. CDT with questions. Affected individuals may obtain a free credit report from each of the following credit reporting bureaus: Equifax 800-525-6285, TransUnion 800-680-7289 , Experian 888-397-3742.
“The organization is taking all necessary and appropriate steps to prevent a recurrence,” Garza said. “Specifically, we will continue to implement administrative, technical and physical safeguards against unauthorized access of protected information. We reported the incident to our email service provider and also are retraining all Seton employees on data protection to enhance vigilance.”
For more information, visit www.seton.net.
