Virus strikes University of Oklahoma computer

A virus recently compromised a clinic computer at the University of Oklahoma-Tulsa neurology practice to possibly retrieve sensitive documents on the machine.

How many victims? 19,264.

What type of personal information? Patient names, telephone numbers, addresses, birth dates, Social Security numbers, medical records, insurance numbers, procedure billing codes, diagnosis codes, lab reports, office notes, radiology reports and service dates. In some records, guarantor information was also included.

What happened? The virus was detected on or about July 28.

Details: It is not possible to determine if any sensitive documents were accessed. Further, neither the university nor the clinic has any indication that the information has been used for illegal or wrongful purposes.

What was the response? An investigation into the incident was initiated after the compromise was discovered. The clinic has implemented steps to ensure the safety and privacy of data, such as increasing the frequency of software and security updates. Letters have been sent to affected patients. Those with questions about the breach are being advised to contact the clinic at (918) 619-4542 or (866) 836-3150.

Sources: News release, “OU Tulsa Neurology Clinic Computer Compromised,” Sept. 24, 2010.
U.S. Department of Health and Human Services, "Breaches Affecting 500 or More Individuals."

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.