Stanford Hospital investigating how patient data ended up on homework help website
Confidential medical data on 20,000 patients potentially compromised
Computerworld - Stanford University Hospital in Palo Alto, Calif. is investigating how a spreadsheet containing personal medical data on 20,000 patients that was being handled by one of its billing contractors ended up publicly available for nearly one year on a homework help site for students.
The spreadsheet first became available on the site last September as an attachment to a question supposedly posed by a student on Student of Fortune, a website that lets students solicit help with their homework for a fee. The question sought help on how the medical data in the attachment could be presented as a bar graph, The New York Times reported on Thursday.
A Stanford Hospital & Clinics representative told Computerworld in a statement that the hospital discovered the file on August 22, and took action to see it was removed within 24 hours.
"A full investigation was launched, and Stanford Hospital & Clinics has been working very aggressively with the vendor to determine how this occurred, in violation of strong contract commitments to safeguard the privacy and security of patient information," the statement said.
The statement identified the third-party as Multi Specialties Collection Services, which it described as an "outside vendor's sub-contractor."
The company is conducting its own investigation into what happened. "The Hospital may take further action following completion of the investigation," the statement said. "This incident was not caused by the Hospital, and responsibility has been assumed," by the third-party contractor, it added.
The spreadsheet contained names, diagnosis codes, account numbers as well as admission and discharge dates for about 20,000 patients who visited the Emergency Room at the hospital in 2009. No Social Security numbers, addresses, birthdates, or credit card details were compromised in the breach. Even so, Stanford has agreed to pay for identity theft monitoring services for the victims.
The hospital learned about the spreadsheet this August when a patient noticed it on the Student of Fortune website and informed the hospital about it. The spreadsheet was taken down immediately once the site learned about it.
Stanford has since suspended its relationship with the billing contractor and has asked it to either destroy or securely return all Stanford patient-related data it currently has in its possession.
The spreadsheet had been prepared by the contractor as part of a billing analysis for the hospital.
Student of Fortune did not immediately respond to a request for comment on the incident. But a spokeswoman for Student of Fortune is quoted in the Times report as saying that the site had been unaware of the data until being informed about it by the hospital at which time it promptly took the information down. The spokeswoman said the identity of the poster cannot be determined.
Data breaches
- Twitter aims to become safer with two-step sign-in
- Yahoo Japan says 22 million user IDs may have been stolen
- Payment card processors hacked in $45 million fraud
- The Onion explains how its Twitter account was hacked
- Name.com forces customers to reset passwords following security breach
- Systems manager arrested for hacking former employer's network
- Dutch bill would give police hacking powers
- After hack, LivingSocial tells 50M users to reset passwords
- Amazon looks to move security appliances to the cloud
- Gh0stRAT malware attacks continue, researcher says
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- The Shape of Email The shape of email is a starting point in helping us understand the qualify of the information residing in the inboxes of organizations...
- sudo or sudoesn't This white paper highlights certain situations where sudo has its place in IT and also shows where it sudoesn't.
- Raising Data Protection Visibility with EMC Data Protection Advisor v6 With better visibility and insight into a key service delivery area like backup, data protection providers can get better information with less effort-and...
- Ransomware: Hijacking Your Data Messages warning that your computer is locked and you need to pay to get back access are very commonplace today. SophosLabs takes an...
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Data Security White Papers | Webcasts
