Patient data available on Google, Yahoo due to security mishap

The health records of more than 30,000 patients at five California hospitals may have been publicly accessible via search engines due to improper server configurations.

How many patients? 31,800 people being treated from February to August 2011 at St. Jute Medical Center, Mission Hospital, Queen of the Valley Medical Center, Santa Rosa Memorial Hospital and Petaluma Valley Hospital.

What type of personal information? Names, blood pressures, lab results, medication allergies and demographic data, as well as other medical details, such as body-mass index, and smoking and advance directive status.

What happened? Incorrect security settings enabled the information to be available on search engines Google and Yahoo. However, to come across the information, one would have had to conduct a detailed search using a string of terms. The data was available from early 2011 through February.

Details: The hospitals were notified about the breach from the lawyer of a patient, who somehow found the data online. Hospital officials contacted the search engine providers to ensure the information was expunged. There is no reason to believe any of the data was misused.

What was the response? Patients were notified by mail.

Quote: "I think that the most important thing is our response was rapid," said Clyde Wesp, chief medical information officer for the St. Joseph Health System.

Source: ocregister.com, The Orange County Register, "Up to 21,300 patients' records put at risk, St. Joseph says," Feb. 16, 2012.

Sign up for our newsletters

POLL

More in The Data Breach Blog

Laptop stolen from S.C. medical center contains data on 7k veterans

Laptop stolen from S.C. medical center contains data ...

Last week, hospital officials began notifying patients of the February theft.

Medical records of 2k patients left unprotected on contractor's server

Medical records of 2k patients left unprotected on ...

The records were stored by storage provider working with Glens Falls Hospital in New York.

Doctor's stolen laptop found at pawn shop; data of 652 patients exposed

The psychologist was a private contractor for Washington's Department of Social and Health Services.