FOLEY, Ala. — If you went to see a doctor in a clinic employed by Foley Clinic Corp. in the last five years, some of your personal information may have been compromised.
SouthBaldwinRegionalMedicalCenter officials have announced that their …
This item is available in full to subscribers.
Please log in to continue |
FOLEY, Ala. — If you went to see a doctor in a clinic employed by Foley Clinic Corp. in the last five years, some of your personal information may have been compromised.
SouthBaldwinRegionalMedicalCenter officials have announced that their parent company of Community Health Systems had a data breach by a foreign-based intruder.
“In July 2014, Community Health Systems Inc. confirmed that its computer network was the target of an external, criminal cyber attack that the company believes occurred in April and June, 2014,” states a CHS news release. “The company and its forensic expert, Mandiant (a FireEye Company), believe the attacker was an ‘advanced persistent threat’ group originating from China who used highly sophisticated malware and technology to attack the company’s systems.”
Kim Neal SBRMC director of marketing and provider relations, said that the transferred data did not include medical information or credit card information.
“But it did include names, addresses, birthdates, telephone numbers and Social Security numbers,” she said in a news release.
Neal explained that officials at Foley Clinic Corp. believe the intruder was likely looking for intellectual property.
“The intruder used highly sophisticated methods to bypass security systems,” she said.
Neal added that the intruder has been eradicated and applications have been deployed to protect against future attacks.
“We are working with federal law enforcement authorities in their investigation and will support prosecution of those responsible for this attack,” she said.
In addition, the medical organization is making sure patients are apprised of the situation.
“Though we have no reason to believe that this data would ever be used, all affected patients are being notified by letter and offered free identity theft protection,” Neal said.
In addition, representatives of SBRMC’s parent company, the Tennessee-based Community Health Systems, say additional measures are being applied to secure its systems.
“Immediately prior to the filing of this report, the company completed eradication of the malware from its systems and finalized the implementation of other remediation efforts that are designed to protect against future intrusions of this type,” the release states.