Menu
Browse

Cyber Incident Victim: Northeast Radiology

Date:

Jan 2020

Location:

United States of America

Summary

Northeast Radiology experienced unauthorized access to its picture archiving and communication system (PACS), which stored radiology images and associated patient information. The breach, discovered by its healthcare management provider Alliance HealthCare Services, prompted an investigation revealing 29 patients' data was definitively accessed, though additional individuals were notified out of caution due to potential exposure. Compromised information included names, demographic details, exam descriptions, medical record numbers, and in some cases Social Security Numbers. While no evidence of data misuse or identity theft was identified, the organization provided credit monitoring services to those whose Social Security Numbers were potentially impacted and established a dedicated inquiry line for affected individuals.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around January 10, 2020, unauthorized individuals gained access to Northeast Radiology's picture archiving and communication system (PACS), a platform used to store radiology images and associated patient information. Alliance HealthCare Services, Northeast Radiology's healthcare management services provider, detected and notified Northeast Radiology of the breach on January 11, 2020. The forensic investigation conducted by Alliance HealthCare Services and Northeast Radiology with assistance from a leading security firm confirmed unauthorized access to the PACS but found no evidence of data misuse, fraud, or identity theft stemming from the incident. The investigation determined that 29 patients' records were definitively accessed by the intruders. While other patient records were present in the system, investigators could not confirm whether additional individuals' data had been accessed.

Cyber Incident Image

Northeast Radiology initiated written notifications on March 11, 2020, to all potentially affected patients for whom contact information was available, including both the confirmed 29 cases and others whose data resided on the compromised system. The potentially exposed information included names, genders, ages, dates of birth, exam descriptions, dates of service, medical images, image descriptions, and medical record numbers. In some instances, medical record numbers corresponded to Social Security Numbers. For patients whose Social Security Numbers were potentially compromised, Northeast Radiology arranged complimentary identity protection and credit monitoring services. The organization established a dedicated inquiry line (1-800-491-8837) for individuals who believed they might be affected but did not receive mailed notifications. Patients were advised to review account statements, credit reports, and contact financial institutions or law enforcement if suspicious activity occurred.

Sources
Sources available to members
1 source