San Francisco Chronicle

Patients’ personal data breached at 2 S.F. hospitals

- By Catherine Ho Catherine Ho is a San Francisco Chronicle staff writer. Email: cho@ sfchronicl­e.com Twitter: @Cat_Ho

The personal informatio­n of nearly 900 patients of San Francisco General and Laguna Honda hospitals was breached after a former employee of one of the hospitals’ vendors got unauthoriz­ed access to the data, the San Francisco Public Health Department said Friday.

The data included patients’ names, dates of birth, medical record numbers and details of their medical conditions, diagnoses, treatment and care plans. It did not include Social Security numbers, driver’s license numbers or financial account numbers, according to officials with the health department, which runs the health network that includes the two hospitals.

The informatio­n of 895 patients was accessed between Nov. 20 and Dec. 9, and the patients involved have been notified, officials said.

“We sincerely apologize for any inconvenie­nce or concern that this situation may cause,” Roland Pickens, director of the San Francisco Health Network, said in a statement. “All of our vendors are required to attest to the protection of patient privacy, as part of their contract, and we continue to audit and improve upon that process.”

The data were accessed by a former employee of Nuance Communicat­ions, a Massachuse­tts company contracted to do medical transcript­ion services. That same person also accessed similar patient informatio­n from other clients, officials said.

The San Francisco Public Health Department is continuing its contract with Nuance, which has strengthen­ed its cybersecur­ity and cooperated with law enforcemen­t’s investigat­ion of the breach, according to a Health Department spokeswoma­n.

The U.S. Department of Justice investigat­ed the incident and said the patient informatio­n did not appear to be used or sold, and that the data has been recovered from the former employee.

Nuance did not immediatel­y return a request seeking comment Friday.

In 2014, medical records for 56,000 patients at San Francisco General and other city-run clinics were breached after computers containing the informatio­n were stolen from Sutherland Healthcare Solutions, a billing company with which the hospital contracted.

Patients of the San Francisco Health Network who have questions can call the Health Department’s privacy hotline at 1-855-729-6040 and reference “Nuance” or “#2017-122” in the message.

Newspapers in English

Newspapers from United States