Source: Unsplash and Markus Spiske

Last year was a big year for data breaches. During the course of 2023, 578 breaches of unsecured protected health information affecting 500 or more individuals were reported. These breaches affected more than 112 million individuals according to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights.

In 2023, over 20 data breaches were reported affecting more than one million individuals. Nashville, Tennessee-based HCA Healthcare notified its patients in August of last year of a breach that may have affected over 11 million people. This was the largest data breach of 2023.

Orthopedic and spine practices were not immune to data breaches and cyberattacks. Included with the nearly 600 reported breaches were a number of significant breaches impacting spine and orthopedic practices.

In November 2023, Seattle, Washington-based Proliance Surgeons reported a breach that affected 437,392 individuals. The breach was a cyberattack in February 2023 that may have involved sensitive personal information, personally identifiable information, and protected health information.

Mississippi Gulf Coast-based Bienville Orthopaedic Specialists LLC reported a data breach in September 2023. The breach affected 242,986 individuals. Bienville Orthopaedic Specialists was sued after reporting the data breach and faces allegations of negligence, breach of implied contract, breach of fiduciary duty, invasion of privacy, and unjust enrichment. For OTW’s coverage of the litigation, see “Bienville Orthopaedic Specialists Sued Over Data Breach.”

Bone & Joint Clinic, S.C. is an orthopedic and pain management clinical practice located in Northcentral Wisconsin. It reported a January 2023 data breach impacting 105,094 individuals including current and former employees as well as current and former patients.

Brooklyn Premier Orthopedics, a full-service orthopedic and pain management center based in Brooklyn, New York, reported a data breach in October 2023. The breach affected 48,459 individuals and may have included patient data such as names, addresses, dates of birth, Social Security numbers, and medical treatment information.

Southeastern Orthopaedic Specialists, PA, an organization made up of two North Carolina-based orthopedic practices, reported a data breach in December 2023. The breach impacted 35,533 individuals. According to its notice of data security incident, the following categories of information may have been exposed: name, demographic information, and reason for office visit.

It doesn’t appear that the data breaches and cyberattacks are slowing down in 2024. Since the beginning of the year, there have already been 14 data breaches reported to the HHS Office for Civil Rights.

 

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.