Memorial Sloan-Kettering Cancer Center patient data compromised

Share this article:

For more than six years, the personal and medical data of hundreds of patients of Memorial Sloan-Kettering Cancer Center (MSKCC) in New York was posted on the internet.

How many victims? 880.

What type of personal information? Names, dates of birth, medical record numbers, dates of treatments, and in some cases Social Security numbers and clinical data.

What happened? A PowerPoint presentation prepared in 2005 for doctors and researchers at the facility accidentally contained embedded sensitive information.

Details: While the data embedded in the charts was not visible to those viewing the presentation, someone accessing the slides via the internet would be capable of manipulating the graphs to expose it. The information was available online from Oct. 16, 2005 to April 13. Sloan-Kettering has since removed the file, which was not encrypted or password protected, from its website and deleted all copies. There is no reason to believe any of the data was misused.

What was done: The facility mailed letters to affected patients, stating that the presentation is no longer in use by staffers and has been deleted from their files.

In a Friday statement, MSKCC said it had taken "significant measures" to bolster its information and data security systems. It also said it was taking steps to prevent future occurrences. 

Source: LongIslandPress.com, "Memorial Sloan-Kettering Patient Data Leak Undetected for 6 Years," June 14, 2012


Share this article:
You must be a registered member of SC Magazine to post a comment.
close

Next Article in The Data Breach Blog

Sign up to our newsletters

RECENT COMMENTS

FOLLOW US

More in The Data Breach Blog

Sourcebooks payment card breach impacts more than 5,000 customers

More than 5,000 customers had personal information stolen, but roughly 9,000 notification letters were sent out as a precautionary measure.

Cyberswim notifies customers that payment card data may be at risk

Malicious software installed on Sept. 24 may have compromised personal information for visitors that made purchases between May 12 and Aug. 28.

Marquette University notifies graduate applicants of possible breach

Settings for an internal file server were inadvertently modified, making graduate school applications accessible to anyone with Marquette University login credentials.