Yale New Haven Hospital website had patient info posted for months
NEW HAVEN — A file containing patient information was posted and available on Yale New Haven Hospital’s website for months, the hospital system said Friday.
The radiology file included patients’ names, telephone numbers, email addresses, age ranges, preferred languages, medical record numbers, procedure types, and dates and locations of the service. The file did not contain Social Security numbers nor financial information, according to Yale New Haven Health in a news release.
The health system said it mailed letters to patients whose information was in the file.
The web file, which was created for research, was unintentionally made accessible through the hospital’s website from Dec. 16, 2021 to April 18, 2022. The hospital learned of the file April 18 and “immediately took steps to ensure the website and content were no longer accessible or searchable via the internet.”
“The file was made accessible through human error, was inadvertent in nature and was not due to intentional or malicious actions,” the hospital system added. Yale New Haven Health also said it used a third-party forensic firm to help in the investigation.
“We deeply regret any inconvenience and concern this incident may cause you. Yale New Haven Hospital understands the importance of maintaining your protected health information, and we take seriously the security of this information,” the organization said in a statement.
As a result, Yale New Haven Health said it has reviewed its security permissions across its internet facing systems and will provide training to remind employees of “their continued need to safeguard patient health information.”
The health system said it will also continue to enhance its existing technical safeguards to further protect its systems and information.
“Yale New Haven Hospital truly regrets any inconvenience or concern this has caused. As a premier health care provider, we strive to demonstrate respect for patients and our community and to always safeguard that information,” the organization added.
The hospital said it has mailed letters to all affected patients. Anyone with concerns are asked to call 855-503-1965.