Computer Theft Affects 4.2 Million

Sutter Health Had Not Yet Encrypted the Device
Computer Theft Affects 4.2 Million
Sutter Health, an integrated delivery system that was in the process of encrypting all its desktop computers, reports that a device that had not yet been encrypted was recently stolen, affecting more than 4.2 million patients.

No patient financial information, Social Security numbers, health plan ID numbers or medical records were on the desktop device, which was stolen during the weekend of Oct. 15 and 16 from an administrative office of the Sutter Medical Foundation, a physician network based in Sacramento, Calif.

The stolen computer contained a database for Sutter Physician Services, which provides billing and other administrative services for 21 Sutter units. That database holds information on about 3.3 million patients collected from 1995 through January 2011. Included are names, addresses, dates of birth, phone numbers, some e-mail addresses, medical record numbers and the name of patients' health insurance plans.

The device also contained a database with more extensive information on 943,000 Sutter Medical Foundation patients, dating from January 2005 to January 2011. This smaller database included the same demographic information as the larger database, plus dates of service and a description of diagnoses and/or procedures.

Sutter Health notes in a statement on its website that it will notify by mail the 943,000 patients who had more extensive information on the computer.

Encryption, Other Steps

"The Sutter Health data security office has already encrypted portable laptops and BlackBerries systemwide and was in the process of encrypting desktop computers throughout the system when the theft took place," according to the statement. "Sutter Health has since accelerated its efforts to encrypt all computers and has implemented routine security software updates. ... Sutter Health also will be reinforcing security practices with staff systemwide."

The healthcare organization has created a toll-free helpline for those who may have been affected and is encouraging patients to review their insurance "explanation of benefits" forms to look for any suspicious billing.

Sutter Health is working with local police on the investigation.


About the Author

Howard Anderson

Howard Anderson

News Editor, ISMG

Howard J. Anderson is news editor of Information Security Media Group and was founding editor of HealthcareInfoSecurity and DataBreachToday. He has more than 34 years of journalism experience, with a focus on healthcare information technology issues. Before launching HealthcareInfoSecurity, he served as founding editor of Health Data Management magazine, where he worked for 17 years, and he served in leadership roles at several other healthcare magazines and newspapers.




Around the Network