Source: Needpix

Tampa Bay, Florida-based Florida Orthopaedic Institute (FOI) has notified its patients of a ransomware attack which may have “accessed or taken” their personal data.

In April 2020, FOI detected that a ransomware attack had encrypted data stored on FOI servers. In response, FOI restored the affected data and put in place additional security measures. FOI also hired a third-party forensic expert to help investigate the matter. From the investigation, FOI learned that FOI patient information may have been “accessed or taken” during the attack.

FOI notified its patients that exposed information may have included: patient names, dates of birth, social security numbers, medical information related to appointment times, physician locations, diagnosis codes, payment amounts, insurance plan identification numbers, payer identification numbers, claims addresses, and/or FOI claims history. FOI does not believe that any of the information involved in the incident has been misused.

FOI is one of the largest orthopedic groups in Florida. Founded in 1989, FOI has over 40 physicians and a professional staff of more than 700. Its size allows it to practice in nearly every orthopedic subspecialty.

The number of data breach incidents has continued to rise. Healthcare data breaches of 500 or more records are reported to the Department of Health and Human Services. The Office for Civil Rights is currently investigating 30 Florida data breaches from the past 24 months.

Vulnerable patients have begun suing hospitals and clinics over attacks on their personal information. For OTW’s previous coverage of recent cybersecurity data breach lawsuits, see “Ozark Orthopaedics Data Breach Exposes Over 15,000 Patients,” “Victims Can Sue Ortho Clinics if Data Hacked,” “Banner Health Agrees to Pay $6 Million for Data Breach,” and “Four Patients Sue DCH Health System After Ransomware Attack.”

For ways to protect your patients and practice against ransomware attacks, see OTW’s previous article, “Tips to Avoid and Mitigate Ransomware Attacks.”

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.