Stanford Hospital investigating how patient data ended up on homework help website
Confidential medical data on 20,000 patients potentially compromised
Computerworld - Stanford University Hospital in Palo Alto, Calif. is investigating how a spreadsheet containing personal medical data on 20,000 patients that was being handled by one of its billing contractors ended up publicly available for nearly one year on a homework help site for students.
The spreadsheet first became available on the site last September as an attachment to a question supposedly posed by a student on Student of Fortune, a website that lets students solicit help with their homework for a fee. The question sought help on how the medical data in the attachment could be presented as a bar graph, The New York Times reported on Thursday.
A Stanford Hospital & Clinics representative told Computerworld in a statement that the hospital discovered the file on August 22, and took action to see it was removed within 24 hours.
"A full investigation was launched, and Stanford Hospital & Clinics has been working very aggressively with the vendor to determine how this occurred, in violation of strong contract commitments to safeguard the privacy and security of patient information," the statement said.
The statement identified the third-party as Multi Specialties Collection Services, which it described as an "outside vendor's sub-contractor."
The company is conducting its own investigation into what happened. "The Hospital may take further action following completion of the investigation," the statement said. "This incident was not caused by the Hospital, and responsibility has been assumed," by the third-party contractor, it added.
The spreadsheet contained names, diagnosis codes, account numbers as well as admission and discharge dates for about 20,000 patients who visited the Emergency Room at the hospital in 2009. No Social Security numbers, addresses, birthdates, or credit card details were compromised in the breach. Even so, Stanford has agreed to pay for identity theft monitoring services for the victims.
The hospital learned about the spreadsheet this August when a patient noticed it on the Student of Fortune website and informed the hospital about it. The spreadsheet was taken down immediately once the site learned about it.
Stanford has since suspended its relationship with the billing contractor and has asked it to either destroy or securely return all Stanford patient-related data it currently has in its possession.
The spreadsheet had been prepared by the contractor as part of a billing analysis for the hospital.
Student of Fortune did not immediately respond to a request for comment on the incident. But a spokeswoman for Student of Fortune is quoted in the Times report as saying that the site had been unaware of the data until being informed about it by the hospital at which time it promptly took the information down. The spokeswoman said the identity of the poster cannot be determined.
- Hackers steal user data from the European Central Bank website, demand money
- Arrests made after international cyber-ring targets StubHub
- SQL injection flaw opens door for Wall Street Journal database hack
- Goodwill Industries probes possible payment card breach
- Aloha point-of-sale terminal, sold on eBay, yields security surprises
- The biggest data breaches of 2014 (so far)
- Blue Shield discloses 18,000 doctors' Social Security numbers
- PF Chang's says breach was 'highly sophisticated criminal operation'
- Breaches exposed 1 in 7 US debit cards in 2013
- New malware program targets banking data
- Aberdeen: Securing the Evolving Datacenter This report highlights ways security technologies and services are evolving to provide the visibility and control needed to deploy workloads flexibly in the...
- Evolving Your Data Center? Evolve Your Data Center Security Your datacenter is evolving - your datacenter security should be evolving, too. Key security technologies and services are being adapted by leading solution...
- Agile Masking Transforms Data Security Most data masking products can create masked data copies but not distribute or update them, resulting in projects that fail to live up...
- Step Out of the Bull's-Eye Learn about the evolution of targeted attacks, the latest in security intelligence, and strategic steps to keep your business safe.
- Live Webcast Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily...
- Will the Real Endpoint Threat Detection and Response Please Stand Up? This webinar explores new technologies & process for protecting endpoints from advanced attackers as well as the innovations that are pushing the envelope... All Data Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!