Two-month delay in notifying patients after cancer center breach

An unencrypted laptop containing patient data was stolen April 30 from the home of a doctor working for The University of Texas M.D. Anderson Cancer Center, but those whose data may have been compromised were not notified until June 28.

How many victims? Nearly 30,000 patients.

What type of personal information? Names, medical record numbers, and treatment and/or research information. Social Security numbers (SSN) were present for a third of patients.

What happened? One day after the unencrypted laptop disappeared from the physician's home on April 30, hospital officials contracted forensic experts to determine what exactly the device contained. Although the investigation determined that there was information on around 30,000 patients, the facility opted to not notify patients until it had a “high degree of certainty” regarding the information because it didn't want "to create unnecessary anxiety."

What's being done: While the hospital said it had been encrypting devices in the past, it will now intensify that program. It also is partnering with law enforcement to find the missing laptop. Those patients whose SSN was breached are eligible for a credit monitoring service paid for by Anderson.

Quote: “We take maintaining and monitoring our patients' health information very seriously, and this is a terrible misfortune,” Dan Fontaine, senior vice president for business affairs at Anderson, said.

Source: bizjournals.com/houston, Houston Business Journal, "M.D. Anderson Cancer Center notifies patients of stolen laptop with personal information," June 28, 2012


close

Next Article in The Data Breach Blog

POLL

More in The Data Breach Blog

Data on patients may be exposed after X-rays go missing

Data on patients may be exposed after X-rays ...

The sensitive information, including names, addresses, and Social Security numbers, went missing from a third-party vendor's warehouse.

Administrative error exposes personal data of 10,200 neurology patients

A routine email sent to Dent Neurologic Institute patients mistakenly included the sensitive data of others receiving treatment.

Website hack leads to credit card breach of nearly 10K at N.C. medical practice

Website hack leads to credit card breach of ...

Other personal information, such as names, contact information and dates of birth, was also compromised.